RAnDomPirice Virus

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: RAnDomPirice Virus

Příspěvekod Damned » 05 led 2014 20:36

Zkus Adw spustit v Nouzovém režimu a vymaž nálezy.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti: Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko Konec.
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje a poté kliknutím na OK spusť program
- nech vybranou možnost Rychlá kontrola a klikni na tlačítko Prohledat

Bude-li nalezen problém:
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost Uložit protokol a ulož si log na Plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
- výsledný log mi sem zkopíruj
(zatím nic nemaž!).

Nebude-li nalezen problém:
- Klikni na tlačítko "OK" a sděl mi to
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Reklama
exoslav
Level 1
Level 1
Příspěvky: 66
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod exoslav » 05 led 2014 21:58

No, něco už jsem smazal předtím, když dělal eset sken. Nicméně sezdá, že ten virus je pryč. Tady je ten log.

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.01.05.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
jirka :: ASUSG60VX [administrátor]

5.1.2014 21:38:59
MBAM-log-2014-01-05 (21-55-33).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 229491
Uplynulý čas: 9 minut, 2 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 2
HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} (PUP.Optional.GreatSaver.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 1
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {7A2FDB90-6258-11E2-AEC4-E4C5E7228958} -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: RAnDomPirice Virus

Příspěvekod Damned » 05 led 2014 22:03

Spusť znovu MbAM a dej Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Konec
**********************************************************************************************
Vypni rezidentní štít antiviru.
Stáhni si ComboFix (by sUBs) a ulož si ho na Plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

exoslav
Level 1
Level 1
Příspěvky: 66
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod exoslav » 06 led 2014 01:07

Zde je log po promazání MbAM:

Malwarebytes Anti-Malware 1.75.0.1300
http://www.malwarebytes.org

Verze: v2014.01.05.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
jirka :: ASUSG60VX [administrátor]

5.1.2014 22:40:32
mbam-log-2014-01-05 (22-40-32).txt

Typ: Kompletní kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 471851
Uplynulý čas: 1 hodin, 28 minut, 16 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 2
HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} (PUP.Optional.GreatSaver.A) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Přesun do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 1
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {7A2FDB90-6258-11E2-AEC4-E4C5E7228958} -> Přesun do karantény a smazání se zdařilo.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\Qoobox\Quarantine\C\ProgramData\BBrowse2saovve\uninstall.exe.vir (PUP.Optional.SilentInstall.A) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.1.0.1_0\mgHelperGCFB.dll (PUP.Optional.SweetIM) -> Přesun do karantény a smazání se zdařilo.

(konec)

Log z Combofixu dodám až ráno

exoslav
Level 1
Level 1
Příspěvky: 66
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod exoslav » 06 led 2014 16:23

Sorry, neměl jsem čas, tak posílám až teď:
LOG Z COMBOXIFU:

ComboFix 14-01-04.03 - jirka 06.01.2014 15:15:46.3.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4095.2625 [GMT 1:00]
Spuštěný z: c:\users\jirka\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\jirka\AppData\Roaming\Local
c:\users\jirka\AppData\Roaming\Local\Skyrim\DLCList.txt
c:\users\jirka\AppData\Roaming\Local\Skyrim\plugins.txt
c:\windows\SysWow64\NSREG.DLL
D:\install.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-06 do 2014-01-06 )))))))))))))))))))))))))))))))
.
.
2014-01-06 14:31 . 2014-01-06 14:31 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-01-06 14:31 . 2014-01-06 14:31 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-01-06 01:30 . 2014-01-06 01:30 -------- d-----w- c:\users\jirka\AppData\Local\ESET
2014-01-05 20:37 . 2014-01-05 20:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-01-05 20:37 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-05 18:22 . 2014-01-05 18:22 388096 ----a-r- c:\users\jirka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-01-05 18:22 . 2014-01-05 18:22 -------- d-----w- c:\program files (x86)\Trend Micro
2014-01-05 18:18 . 2014-01-05 18:18 -------- d-----w- c:\users\jirka\AppData\Local\ElevatedDiagnostics
2014-01-05 15:31 . 2014-01-05 15:31 -------- d-----w- c:\program files\ESET
2014-01-05 15:26 . 2014-01-05 15:26 -------- d-s---w- c:\windows\SysWow64\Microsoft
2014-01-05 14:15 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7CBE79E0-4E9A-436A-9856-287C1A9BC82F}\mpengine.dll
2014-01-05 13:56 . 2014-01-05 20:32 -------- d-----w- C:\AdwCleaner
2014-01-04 13:04 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-31 02:55 . 2014-01-05 14:02 -------- d-----w- c:\programdata\RAnDomPirice
2013-12-30 16:33 . 2013-12-30 16:33 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-12-30 16:32 . 2014-01-05 12:42 -------- d-----w- c:\program files (x86)\Steam
2013-12-27 09:14 . 2013-12-27 09:14 -------- d-----w- c:\programdata\WinSpeed
2013-12-25 23:15 . 2013-12-25 23:15 -------- d-----w- c:\program files\Codemasters
2013-12-24 00:05 . 2013-12-24 00:05 -------- d-----w- c:\programdata\Titanium
2013-12-24 00:04 . 2013-12-24 00:04 -------- d-----w- c:\users\jirka\AppData\Roaming\Titanium
2013-12-20 23:16 . 2013-12-27 21:12 -------- d-----w- c:\programdata\WarThunder
2013-12-20 23:16 . 2013-12-20 23:16 -------- d-----w- c:\users\jirka\AppData\Local\WarThunder
2013-12-20 23:07 . 2014-01-05 11:57 -------- d-----w- c:\program files (x86)\WarThunder
2013-12-15 15:53 . 2013-12-29 14:53 -------- d-----w- c:\programdata\Microsoft Games
2013-12-15 15:52 . 2013-12-15 15:52 -------- d-----w- c:\program files (x86)\Oberon Media
2013-12-12 14:19 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-12 14:19 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-12 14:19 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 14:19 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-12 14:19 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 11:23 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-26 16:30 . 2013-09-17 21:47 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-12-26 16:30 . 2013-09-17 21:48 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-12-26 16:30 . 2011-07-29 19:55 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-12-26 16:28 . 2013-09-17 21:48 280856 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-12-15 05:52 . 2011-07-13 07:01 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-11 18:52 . 2012-06-06 21:35 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-11 18:52 . 2011-07-13 06:34 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-27 00:16 . 2013-11-27 00:16 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-27 00:16 . 2013-11-27 00:16 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-27 00:16 . 2013-11-27 00:16 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-27 00:16 . 2013-11-27 00:16 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-27 00:16 . 2013-11-27 00:16 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-27 00:16 . 2013-11-27 00:16 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-27 00:16 . 2013-11-27 00:16 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-27 00:16 . 2013-11-27 00:16 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-27 00:16 . 2013-11-27 00:16 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-27 00:16 . 2013-11-27 00:16 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-27 00:16 . 2013-11-27 00:16 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-27 00:16 . 2013-11-27 00:16 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-27 00:16 . 2013-11-27 00:16 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-27 00:16 . 2013-11-27 00:16 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-27 00:16 . 2013-11-27 00:16 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-27 00:16 . 2013-11-27 00:16 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-27 00:16 . 2013-11-27 00:16 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-27 00:16 . 2013-11-27 00:16 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-27 00:16 . 2013-11-27 00:16 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-27 00:16 . 2013-11-27 00:16 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-27 00:16 . 2013-11-27 00:16 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-27 00:16 . 2013-11-27 00:16 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-27 00:16 . 2013-11-27 00:16 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-27 00:16 . 2013-11-27 00:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-27 00:16 . 2013-11-27 00:16 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-27 00:16 . 2013-11-27 00:16 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-27 00:16 . 2013-11-27 00:16 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-27 00:16 . 2013-11-27 00:16 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-27 00:16 . 2013-11-27 00:16 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-27 00:16 . 2013-11-27 00:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-27 00:16 . 2013-11-27 00:16 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-27 00:16 . 2013-11-27 00:16 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-27 00:16 . 2013-11-27 00:16 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-27 00:16 . 2013-11-27 00:16 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-27 00:16 . 2013-11-27 00:16 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-27 00:16 . 2013-11-27 00:16 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-27 00:16 . 2013-11-27 00:16 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-27 00:16 . 2013-11-27 00:16 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-27 00:16 . 2013-11-27 00:16 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-27 00:16 . 2013-11-27 00:16 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-27 00:16 . 2013-11-27 00:16 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-27 00:16 . 2013-11-27 00:16 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-27 00:16 . 2013-11-27 00:16 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-27 00:16 . 2013-11-27 00:16 413696 ----a-w- c:\windows\system32\html.iec
2013-11-27 00:16 . 2013-11-27 00:16 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-27 00:16 . 2013-11-27 00:16 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-27 00:16 . 2013-11-27 00:16 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-27 00:16 . 2013-11-27 00:16 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-27 00:16 . 2013-11-27 00:16 235520 ----a-w- c:\windows\system32\url.dll
2013-11-27 00:16 . 2013-11-27 00:16 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-27 00:16 . 2013-11-27 00:16 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-27 00:16 . 2013-11-27 00:16 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-27 00:16 . 2013-11-27 00:16 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-27 00:16 . 2013-11-27 00:16 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-27 00:16 . 2013-11-27 00:16 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-27 00:16 . 2013-11-27 00:16 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-19 10:21 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-14 12:05 . 2013-11-14 12:05 35352 ----a-w- c:\windows\system32\drivers\cnnctfy3.sys
2013-11-10 21:51 . 2011-07-13 09:57 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-10-20 18:54 . 2013-12-07 09:46 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4445BC28-75EF-40E2-BB55-20759D8BDEC5}\gapaengine.dll
2013-10-20 18:54 . 2011-08-11 09:49 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-10-14 17:00 . 2013-11-27 00:20 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-10-12 02:30 . 2013-11-13 14:04 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-13 14:04 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-13 14:04 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-13 14:04 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-13 14:04 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"LightShot"="c:\users\jirka\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2013-09-27 226592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
.
c:\users\jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-1-6 36024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SecureUpdateSvc;SecureUpdate;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys;c:\windows\SYSNATIVE\DRIVERS\ipswuio.sys [x]
R3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 PSI_SVC_2_x64;Protexis Licensing V2 x64;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SolutoRemoteService;Soluto Remote Service;c:\program files\Soluto\SolutoRemoteService.exe;c:\program files\Soluto\SolutoRemoteService.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys;c:\windows\SYSNATIVE\DRIVERS\Soluto.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 f1f78e38;WinSpeed;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;c:\program files\Soluto\SolutoLauncherService.exe;c:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe;c:\program files\Soluto\SolutoService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 NETw5s64;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
start [BU]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-05 17:10 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-06 18:52]
.
2013-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 14:52]
.
2014-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 14:52]
.
2014-01-05 c:\windows\Tasks\Norton Security Scan for jirka.job
- c:\progra~2\NORTON~2\Engine\352~1.10\Nss.exe [2011-09-24 15:16]
.
2014-01-06 c:\windows\Tasks\update-S-1-5-21-863027704-3670233696-608825480-1000.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2013-12-01 12:37]
.
2014-01-06 c:\windows\Tasks\update-sys.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2013-12-01 12:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-31 8095776]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-04-24 7477016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
"Soluto"="c:\program files\soluto\soluto.exe" [2013-01-10 1229296]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: ????3?? - c:\users\jirka\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\jirka\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\jirka\AppData\Roaming\Mozilla\Firefox\Profiles\qapcx82j.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
BHO-{A41C31A5-3185-908D-032C-DD8AA2095ACE} - c:\programdata\DoIscountExtensoI\Vjx.x64.dll
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-BitLord - c:\program files (x86)\BitLord 2\Bitlord-uninst.exe
AddRemove-PIXELRULER - c:\windows\system32\mioengine.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3* N}Ź]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3* N}ŹhQčţ”Ąc]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\users\jirka\AppData\Local\Skillbrains\lightshot\4.4.2.10\LightShot.exe
.
**************************************************************************
.
Celkový čas: 2014-01-06 16:02:02 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-06 15:01
ComboFix2.txt 2013-04-30 19:42
.
Před spuštěním: Volných bajtů: 47 321 501 696
Po spuštění: Volných bajtů: 47 017 246 720
.
- - End Of File - - 352FE686DD3836581A1BCC62B495E51A
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod memphisto » 07 led 2014 16:18

Máš tam dva antiviry. ESET a MSE. Jeden odinstaluj a znovu Combofix
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

exoslav
Level 1
Level 1
Příspěvky: 66
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod exoslav » 14 led 2014 04:00

Tak tady je log z kombofixu. Už mám v pc jen eset a tne jsem na dobu, co běžel combofix, vypnul.

ComboFix 14-01-04.03 - jirka 14.01.2014 3:10.4.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4095.2921 [GMT 1:00]
Spuštěný z: c:\users\jirka\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
D:\install.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-14 do 2014-01-14 )))))))))))))))))))))))))))))))
.
.
2014-01-14 02:27 . 2014-01-14 02:27 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-01-14 02:27 . 2014-01-14 02:27 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-01-12 14:50 . 2014-01-14 02:18 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A0521F5D-7359-4635-9409-BEC9C027D7A4}\offreg.dll
2014-01-10 12:43 . 2013-12-16 00:54 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A0521F5D-7359-4635-9409-BEC9C027D7A4}\mpengine.dll
2014-01-09 16:36 . 2014-01-09 16:36 -------- d-----w- c:\users\jirka\AppData\Roaming\TeamViewer
2014-01-09 16:27 . 2014-01-09 16:27 -------- d-----w- c:\program files (x86)\TeamViewer
2014-01-07 19:06 . 2014-01-09 19:18 -------- d-----w- c:\users\jirka\AppData\Roaming\BitLord
2014-01-07 19:06 . 2014-01-07 19:06 -------- d-----w- c:\users\jirka\.android
2014-01-07 19:06 . 2014-01-07 19:06 -------- d-----w- c:\users\jirka\AppData\Local\cache
2014-01-07 19:06 . 2014-01-13 19:49 -------- d-----w- c:\users\jirka\AppData\Roaming\newnext.me
2014-01-07 19:06 . 2014-01-07 19:09 -------- d-----w- c:\users\jirka\AppData\Local\Mobogenie
2014-01-07 19:06 . 2014-01-07 19:06 -------- d-----w- c:\users\jirka\AppData\Local\genienext
2014-01-07 19:05 . 2014-01-07 19:09 -------- d-----w- c:\program files (x86)\Mobogenie
2014-01-07 19:04 . 2014-01-07 19:04 -------- d-----w- c:\program files (x86)\BitLord 2
2014-01-06 01:30 . 2014-01-06 01:30 -------- d-----w- c:\users\jirka\AppData\Local\ESET
2014-01-05 20:37 . 2014-01-05 20:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-01-05 20:37 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-05 18:22 . 2014-01-05 18:22 388096 ----a-r- c:\users\jirka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-01-05 18:22 . 2014-01-05 18:22 -------- d-----w- c:\program files (x86)\Trend Micro
2014-01-05 18:18 . 2014-01-05 18:18 -------- d-----w- c:\users\jirka\AppData\Local\ElevatedDiagnostics
2014-01-05 15:31 . 2014-01-05 15:31 -------- d-----w- c:\program files\ESET
2014-01-05 15:26 . 2014-01-05 15:26 -------- d-s---w- c:\windows\SysWow64\Microsoft
2014-01-05 13:56 . 2014-01-05 20:32 -------- d-----w- C:\AdwCleaner
2013-12-31 02:55 . 2014-01-05 14:02 -------- d-----w- c:\programdata\RAnDomPirice
2013-12-30 16:33 . 2013-12-30 16:33 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-12-30 16:32 . 2014-01-05 12:42 -------- d-----w- c:\program files (x86)\Steam
2013-12-27 09:14 . 2014-01-13 12:44 -------- d-----w- c:\programdata\WinSpeed
2013-12-25 23:15 . 2013-12-25 23:15 -------- d-----w- c:\program files\Codemasters
2013-12-24 00:05 . 2013-12-24 00:05 -------- d-----w- c:\programdata\Titanium
2013-12-24 00:04 . 2013-12-24 00:04 -------- d-----w- c:\users\jirka\AppData\Roaming\Titanium
2013-12-20 23:16 . 2013-12-27 21:12 -------- d-----w- c:\programdata\WarThunder
2013-12-20 23:16 . 2013-12-20 23:16 -------- d-----w- c:\users\jirka\AppData\Local\WarThunder
2013-12-20 23:07 . 2014-01-05 11:57 -------- d-----w- c:\program files (x86)\WarThunder
2013-12-15 15:53 . 2013-12-29 14:53 -------- d-----w- c:\programdata\Microsoft Games
2013-12-15 15:52 . 2013-12-15 15:52 -------- d-----w- c:\program files (x86)\Oberon Media
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-26 16:30 . 2013-09-17 21:47 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-12-26 16:30 . 2013-09-17 21:48 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-12-26 16:30 . 2011-07-29 19:55 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-12-26 16:28 . 2013-09-17 21:48 280856 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-12-15 05:52 . 2011-07-13 07:01 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-11 18:52 . 2012-06-06 21:35 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-11 18:52 . 2011-07-13 06:34 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-27 00:16 . 2013-11-27 00:16 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-27 00:16 . 2013-11-27 00:16 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-27 00:16 . 2013-11-27 00:16 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-27 00:16 . 2013-11-27 00:16 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-27 00:16 . 2013-11-27 00:16 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-27 00:16 . 2013-11-27 00:16 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-27 00:16 . 2013-11-27 00:16 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-27 00:16 . 2013-11-27 00:16 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-27 00:16 . 2013-11-27 00:16 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-27 00:16 . 2013-11-27 00:16 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-27 00:16 . 2013-11-27 00:16 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-27 00:16 . 2013-11-27 00:16 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-27 00:16 . 2013-11-27 00:16 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-27 00:16 . 2013-11-27 00:16 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-27 00:16 . 2013-11-27 00:16 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-27 00:16 . 2013-11-27 00:16 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-27 00:16 . 2013-11-27 00:16 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-27 00:16 . 2013-11-27 00:16 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-27 00:16 . 2013-11-27 00:16 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-27 00:16 . 2013-11-27 00:16 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-27 00:16 . 2013-11-27 00:16 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-27 00:16 . 2013-11-27 00:16 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-27 00:16 . 2013-11-27 00:16 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-27 00:16 . 2013-11-27 00:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-27 00:16 . 2013-11-27 00:16 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-27 00:16 . 2013-11-27 00:16 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-27 00:16 . 2013-11-27 00:16 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-27 00:16 . 2013-11-27 00:16 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-27 00:16 . 2013-11-27 00:16 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-27 00:16 . 2013-11-27 00:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-27 00:16 . 2013-11-27 00:16 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-27 00:16 . 2013-11-27 00:16 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-27 00:16 . 2013-11-27 00:16 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-27 00:16 . 2013-11-27 00:16 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-27 00:16 . 2013-11-27 00:16 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-27 00:16 . 2013-11-27 00:16 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-27 00:16 . 2013-11-27 00:16 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-27 00:16 . 2013-11-27 00:16 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-27 00:16 . 2013-11-27 00:16 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-27 00:16 . 2013-11-27 00:16 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-27 00:16 . 2013-11-27 00:16 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-27 00:16 . 2013-11-27 00:16 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-27 00:16 . 2013-11-27 00:16 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-27 00:16 . 2013-11-27 00:16 413696 ----a-w- c:\windows\system32\html.iec
2013-11-27 00:16 . 2013-11-27 00:16 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-27 00:16 . 2013-11-27 00:16 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-27 00:16 . 2013-11-27 00:16 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-27 00:16 . 2013-11-27 00:16 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-27 00:16 . 2013-11-27 00:16 235520 ----a-w- c:\windows\system32\url.dll
2013-11-27 00:16 . 2013-11-27 00:16 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-27 00:16 . 2013-11-27 00:16 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-27 00:16 . 2013-11-27 00:16 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-27 00:16 . 2013-11-27 00:16 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-27 00:16 . 2013-11-27 00:16 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-27 00:16 . 2013-11-27 00:16 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-27 00:16 . 2013-11-27 00:16 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-26 11:54 . 2013-12-12 14:17 23183360 ----a-w- c:\windows\system32\mshtml.dll
2013-11-26 11:25 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-26 10:19 . 2013-12-12 14:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 10:18 . 2013-12-12 14:17 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 09:48 . 2013-12-12 14:17 66048 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 09:46 . 2013-12-12 14:17 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 09:41 . 2013-12-12 14:17 2764288 ----a-w- c:\windows\system32\iertutil.dll
2013-11-26 09:29 . 2013-12-12 14:17 53760 ----a-w- c:\windows\system32\jsproxy.dll
2013-11-26 09:27 . 2013-12-12 14:17 33792 ----a-w- c:\windows\system32\iernonce.dll
2013-11-26 09:23 . 2013-12-12 14:17 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-26 09:21 . 2013-12-12 14:17 574976 ----a-w- c:\windows\system32\ieui.dll
2013-11-26 09:18 . 2013-12-12 14:17 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 09:18 . 2013-12-12 14:17 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 09:16 . 2013-12-12 14:17 708608 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:57 . 2013-12-12 14:17 218624 ----a-w- c:\windows\system32\ie4uinit.exe
2013-11-26 08:35 . 2013-12-12 14:17 5769216 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 08:28 . 2013-12-12 14:17 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2013-11-26 08:16 . 2013-12-12 14:17 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-11-26 08:02 . 2013-12-12 14:17 1995264 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 07:48 . 2013-12-12 14:17 12996608 ----a-w- c:\windows\system32\ieframe.dll
2013-11-26 07:32 . 2013-12-12 14:17 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-11-26 07:07 . 2013-12-12 14:17 2334208 ----a-w- c:\windows\system32\wininet.dll
2013-11-26 06:40 . 2013-12-12 14:17 1395200 ----a-w- c:\windows\system32\urlmon.dll
2013-11-26 06:34 . 2013-12-12 14:17 817664 ----a-w- c:\windows\system32\ieapfltr.dll
2013-11-26 06:33 . 2013-12-12 14:17 1820160 ----a-w- c:\windows\SysWow64\wininet.dll
2013-11-23 18:26 . 2013-12-12 11:23 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-12 11:23 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-14 12:05 . 2013-11-14 12:05 35352 ----a-w- c:\windows\system32\drivers\cnnctfy3.sys
2013-11-12 02:23 . 2013-12-12 11:23 2048 ----a-w- c:\windows\system32\tzres.dll
2013-11-12 02:07 . 2013-12-12 11:23 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-11-10 21:51 . 2011-07-13 09:57 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-10-30 02:32 . 2013-12-12 11:23 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-10-30 02:19 . 2013-12-12 11:23 301568 ----a-w- c:\windows\SysWow64\msieftp.dll
2013-10-30 01:24 . 2013-12-12 11:23 3155968 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"LightShot"="c:\users\jirka\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2013-09-27 226592]
"NextLive"="c:\users\jirka\AppData\Roaming\newnext.me\nengine.dll" [2013-11-14 1283584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
.
c:\users\jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-1-6 36024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 f1f78e38;WinSpeed;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
R2 SecureUpdateSvc;SecureUpdate;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys;c:\windows\SYSNATIVE\DRIVERS\ipswuio.sys [x]
R3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 PSI_SVC_2_x64;Protexis Licensing V2 x64;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SolutoRemoteService;Soluto Remote Service;c:\program files\Soluto\SolutoRemoteService.exe;c:\program files\Soluto\SolutoRemoteService.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys;c:\windows\SYSNATIVE\DRIVERS\Soluto.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;c:\program files\Soluto\SolutoLauncherService.exe;c:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe;c:\program files\Soluto\SolutoService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 NETw5s64;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
start [BU]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-05 17:10 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-06 18:52]
.
2013-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 14:52]
.
2014-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 14:52]
.
2014-01-12 c:\windows\Tasks\Norton Security Scan for jirka.job
- c:\progra~2\NORTON~2\Engine\352~1.10\Nss.exe [2011-09-24 15:16]
.
2014-01-14 c:\windows\Tasks\update-S-1-5-21-863027704-3670233696-608825480-1000.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2013-12-01 12:37]
.
2014-01-14 c:\windows\Tasks\update-sys.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2013-12-01 12:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A41C31A5-3185-908D-032C-DD8AA2095ACE}]
c:\programdata\DoIscountExtensoI\Vjx.x64.dll [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-31 8095776]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-04-24 7477016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
"Soluto"="c:\program files\soluto\soluto.exe" [2013-01-10 1229296]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: ????3?? - c:\users\jirka\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\jirka\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\jirka\AppData\Roaming\Mozilla\Firefox\Profiles\qapcx82j.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-mobilegeni daemon - c:\program files (x86)\Mobogenie\DaemonProcess.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-PIXELRULER - c:\windows\system32\mioengine.exe
AddRemove-{5F189DF5-2D05-472B-9091-84D9848AE48B}{f1f78e38} - c:\progra~3\WinSpeed\WinSpeed.dll
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3* N}Ź]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3* N}ŹhQčţ”Ąc]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-01-14 03:56:15
ComboFix-quarantined-files.txt 2014-01-14 02:56
ComboFix2.txt 2014-01-06 15:02
ComboFix3.txt 2013-04-30 19:42
.
Před spuštěním: Volných bajtů: 45 413 642 240
Po spuštění: Volných bajtů: 48 353 001 472
.
- - End Of File - - 9BF25D84534FB117B5D0371B5CFC211E
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod jaro3 » 14 led 2014 10:54

Odinstaluj:
Norton Security Scan

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\Norton Security Scan for jirka.job

Folder::
c:\program files (x86)\Google\Update
c:\progra~2\NORTON~2

Driver::
f1f78e38
SkypeUpdate

RegLock::
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*
N}Ź]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*
N}ŹhQčţ”Ąc]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\programdata\DoIscountExtensoI\Vjx.x64.dll

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

exoslav
Level 1
Level 1
Příspěvky: 66
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod exoslav » 14 led 2014 18:30

- No, HiJcakThis mi nejde spustit, píše to ten error 362 (nebo tak nějak), už jsem to předtím psal
- Složku DoIscount nemůžu nalézt, i když mám povolené zobrazení skrytých souborů
- Ten Combofix jsem pustil i se skriptem, log zde:

ComboFix 14-01-04.03 - jirka 14.01.2014 17:59:14.5.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4095.2577 [GMT 1:00]
Spuštěný z: c:\users\jirka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\jirka\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\Norton Security Scan for jirka.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.22.3\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.22.3\goopdate.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.22.3\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.22.3\psmachine.dll
c:\program files (x86)\Google\Update\1.3.22.3\psuser.dll
c:\program files (x86)\Google\Update\Download\{2BF2CA35-CCAF-4E58-BAB7-4163BFA03B88}\7.1.2.2041\GoogleEarth-Win-Plugin-7.1.2.2041.exe
c:\program files (x86)\Google\Update\Download\{3C122445-AECE-4309-90B7-85A6AEF42AC0}\0.0.0.0\gsync.msi
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.3\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\31.0.1650.63\31.0.1650.63_31.0.1650.57_chrome_updater.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_f1f78e38
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-14 do 2014-01-14 )))))))))))))))))))))))))))))))
.
.
2014-01-07 19:06 . 2014-01-07 19:09 -------- d-----w- c:\users\jirka\AppData\Local\Mobogenie
2014-01-07 19:06 . 2014-01-07 19:06 -------- d-----w- c:\users\jirka\AppData\Local\genienext
2014-01-07 19:05 . 2014-01-07 19:09 -------- d-----w- c:\program files (x86)\Mobogenie
2014-01-07 19:04 . 2014-01-07 19:04 -------- d-----w- c:\program files (x86)\BitLord 2
2014-01-06 01:30 . 2014-01-06 01:30 -------- d-----w- c:\users\jirka\AppData\Local\ESET
2014-01-05 20:37 . 2014-01-05 20:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-01-05 20:37 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-05 18:22 . 2014-01-05 18:22 388096 ----a-r- c:\users\jirka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-01-05 18:22 . 2014-01-05 18:22 -------- d-----w- c:\program files (x86)\Trend Micro
2014-01-05 18:18 . 2014-01-05 18:18 -------- d-----w- c:\users\jirka\AppData\Local\ElevatedDiagnostics
2014-01-05 15:31 . 2014-01-05 15:31 -------- d-----w- c:\program files\ESET
2014-01-05 15:26 . 2014-01-05 15:26 -------- d-s---w- c:\windows\SysWow64\Microsoft
2014-01-05 13:56 . 2014-01-05 20:32 -------- d-----w- C:\AdwCleaner
2013-12-31 02:55 . 2014-01-05 14:02 -------- d-----w- c:\programdata\RAnDomPirice
2013-12-30 16:33 . 2013-12-30 16:33 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-12-30 16:32 . 2014-01-05 12:42 -------- d-----w- c:\program files (x86)\Steam
2013-12-27 09:14 . 2014-01-13 12:44 -------- d-----w- c:\programdata\WinSpeed
2013-12-25 23:15 . 2013-12-25 23:15 -------- d-----w- c:\program files\Codemasters
2013-12-24 00:05 . 2013-12-24 00:05 -------- d-----w- c:\programdata\Titanium
2013-12-24 00:04 . 2013-12-24 00:04 -------- d-----w- c:\users\jirka\AppData\Roaming\Titanium
2013-12-20 23:16 . 2013-12-27 21:12 -------- d-----w- c:\programdata\WarThunder
2013-12-20 23:16 . 2013-12-20 23:16 -------- d-----w- c:\users\jirka\AppData\Local\WarThunder
2013-12-20 23:07 . 2014-01-05 11:57 -------- d-----w- c:\program files (x86)\WarThunder
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-26 16:30 . 2013-09-17 21:47 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-12-26 16:30 . 2013-09-17 21:48 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-12-26 16:30 . 2011-07-29 19:55 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-12-26 16:28 . 2013-09-17 21:48 280856 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-12-15 05:52 . 2011-07-13 07:01 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-11 18:52 . 2012-06-06 21:35 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-11 18:52 . 2011-07-13 06:34 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-27 00:16 . 2013-11-27 00:16 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-27 00:16 . 2013-11-27 00:16 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-27 00:16 . 2013-11-27 00:16 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-27 00:16 . 2013-11-27 00:16 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-27 00:16 . 2013-11-27 00:16 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-27 00:16 . 2013-11-27 00:16 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-27 00:16 . 2013-11-27 00:16 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-27 00:16 . 2013-11-27 00:16 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-27 00:16 . 2013-11-27 00:16 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-27 00:16 . 2013-11-27 00:16 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-27 00:16 . 2013-11-27 00:16 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-27 00:16 . 2013-11-27 00:16 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-27 00:16 . 2013-11-27 00:16 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-27 00:16 . 2013-11-27 00:16 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-27 00:16 . 2013-11-27 00:16 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-27 00:16 . 2013-11-27 00:16 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-27 00:16 . 2013-11-27 00:16 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-27 00:16 . 2013-11-27 00:16 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-27 00:16 . 2013-11-27 00:16 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-27 00:16 . 2013-11-27 00:16 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-27 00:16 . 2013-11-27 00:16 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-27 00:16 . 2013-11-27 00:16 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-27 00:16 . 2013-11-27 00:16 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-27 00:16 . 2013-11-27 00:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-27 00:16 . 2013-11-27 00:16 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-27 00:16 . 2013-11-27 00:16 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-27 00:16 . 2013-11-27 00:16 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-27 00:16 . 2013-11-27 00:16 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-27 00:16 . 2013-11-27 00:16 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-27 00:16 . 2013-11-27 00:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-27 00:16 . 2013-11-27 00:16 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-27 00:16 . 2013-11-27 00:16 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-27 00:16 . 2013-11-27 00:16 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-27 00:16 . 2013-11-27 00:16 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-27 00:16 . 2013-11-27 00:16 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-27 00:16 . 2013-11-27 00:16 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-27 00:16 . 2013-11-27 00:16 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-27 00:16 . 2013-11-27 00:16 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-27 00:16 . 2013-11-27 00:16 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-27 00:16 . 2013-11-27 00:16 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-27 00:16 . 2013-11-27 00:16 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-27 00:16 . 2013-11-27 00:16 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-27 00:16 . 2013-11-27 00:16 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-27 00:16 . 2013-11-27 00:16 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-27 00:16 . 2013-11-27 00:16 413696 ----a-w- c:\windows\system32\html.iec
2013-11-27 00:16 . 2013-11-27 00:16 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-27 00:16 . 2013-11-27 00:16 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-27 00:16 . 2013-11-27 00:16 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-27 00:16 . 2013-11-27 00:16 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-27 00:16 . 2013-11-27 00:16 235520 ----a-w- c:\windows\system32\url.dll
2013-11-27 00:16 . 2013-11-27 00:16 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-27 00:16 . 2013-11-27 00:16 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-27 00:16 . 2013-11-27 00:16 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-27 00:16 . 2013-11-27 00:16 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-27 00:16 . 2013-11-27 00:16 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-27 00:16 . 2013-11-27 00:16 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-27 00:16 . 2013-11-27 00:16 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-26 11:54 . 2013-12-12 14:17 23183360 ----a-w- c:\windows\system32\mshtml.dll
2013-11-26 11:25 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-26 10:19 . 2013-12-12 14:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 10:18 . 2013-12-12 14:17 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 09:48 . 2013-12-12 14:17 66048 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 09:46 . 2013-12-12 14:17 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 09:41 . 2013-12-12 14:17 2764288 ----a-w- c:\windows\system32\iertutil.dll
2013-11-26 09:29 . 2013-12-12 14:17 53760 ----a-w- c:\windows\system32\jsproxy.dll
2013-11-26 09:27 . 2013-12-12 14:17 33792 ----a-w- c:\windows\system32\iernonce.dll
2013-11-26 09:23 . 2013-12-12 14:17 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-26 09:21 . 2013-12-12 14:17 574976 ----a-w- c:\windows\system32\ieui.dll
2013-11-26 09:18 . 2013-12-12 14:17 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 09:18 . 2013-12-12 14:17 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 09:16 . 2013-12-12 14:17 708608 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:57 . 2013-12-12 14:17 218624 ----a-w- c:\windows\system32\ie4uinit.exe
2013-11-26 08:35 . 2013-12-12 14:17 5769216 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 08:28 . 2013-12-12 14:17 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2013-11-26 08:16 . 2013-12-12 14:17 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-11-26 08:02 . 2013-12-12 14:17 1995264 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 07:48 . 2013-12-12 14:17 12996608 ----a-w- c:\windows\system32\ieframe.dll
2013-11-26 07:32 . 2013-12-12 14:17 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-11-26 07:07 . 2013-12-12 14:17 2334208 ----a-w- c:\windows\system32\wininet.dll
2013-11-26 06:40 . 2013-12-12 14:17 1395200 ----a-w- c:\windows\system32\urlmon.dll
2013-11-26 06:34 . 2013-12-12 14:17 817664 ----a-w- c:\windows\system32\ieapfltr.dll
2013-11-26 06:33 . 2013-12-12 14:17 1820160 ----a-w- c:\windows\SysWow64\wininet.dll
2013-11-23 18:26 . 2013-12-12 11:23 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-12 11:23 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-14 12:05 . 2013-11-14 12:05 35352 ----a-w- c:\windows\system32\drivers\cnnctfy3.sys
2013-11-12 02:23 . 2013-12-12 11:23 2048 ----a-w- c:\windows\system32\tzres.dll
2013-11-12 02:07 . 2013-12-12 11:23 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-11-10 21:51 . 2011-07-13 09:57 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-10-30 02:32 . 2013-12-12 11:23 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-10-30 02:19 . 2013-12-12 11:23 301568 ----a-w- c:\windows\SysWow64\msieftp.dll
2013-10-30 01:24 . 2013-12-12 11:23 3155968 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"LightShot"="c:\users\jirka\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2013-09-27 226592]
"NextLive"="c:\users\jirka\AppData\Roaming\newnext.me\nengine.dll" [2013-11-14 1283584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
.
c:\users\jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-1-6 36024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SecureUpdateSvc;SecureUpdate;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [x]
R3 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys;c:\windows\SYSNATIVE\DRIVERS\ipswuio.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 PSI_SVC_2_x64;Protexis Licensing V2 x64;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SolutoRemoteService;Soluto Remote Service;c:\program files\Soluto\SolutoRemoteService.exe;c:\program files\Soluto\SolutoRemoteService.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys;c:\windows\SYSNATIVE\DRIVERS\Soluto.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;c:\program files\Soluto\SolutoLauncherService.exe;c:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe;c:\program files\Soluto\SolutoService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 NETw5s64;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
start [BU]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-05 17:10 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-06 18:52]
.
2014-01-14 c:\windows\Tasks\update-S-1-5-21-863027704-3670233696-608825480-1000.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2013-12-01 12:37]
.
2014-01-14 c:\windows\Tasks\update-sys.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2013-12-01 12:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A41C31A5-3185-908D-032C-DD8AA2095ACE}]
c:\programdata\DoIscountExtensoI\Vjx.x64.dll [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-12-06 14:47 778704 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-31 8095776]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-04-24 7477016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
"Soluto"="c:\program files\soluto\soluto.exe" [2013-01-10 1229296]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: ????3?? - c:\users\jirka\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\jirka\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\jirka\AppData\Roaming\Mozilla\Firefox\Profiles\qapcx82j.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-PIXELRULER - c:\windows\system32\mioengine.exe
AddRemove-{5F189DF5-2D05-472B-9091-84D9848AE48B}{f1f78e38} - c:\progra~3\WinSpeed\WinSpeed.dll
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3* N}Ź]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-863027704-3670233696-608825480-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3* N}ŹhQčţ”Ąc]
@="c:\\Users\\jirka\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\SysWOW64\rundll32.exe
c:\users\jirka\AppData\Local\Skillbrains\lightshot\4.4.2.10\LightShot.exe
.
**************************************************************************
.
Celkový čas: 2014-01-14 18:14:40 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-14 17:14
ComboFix2.txt 2014-01-14 02:56
ComboFix3.txt 2014-01-06 15:02
ComboFix4.txt 2013-04-30 19:42
.
Před spuštěním: Volných bajtů: 48 269 459 456
Po spuštění: Volných bajtů: 48 005 394 432
.
- - End Of File - - DEE420B2C48C39C7C51C31B7C3AD0A1C
A36C5E4F47E84449FF07ED3517B43A31


A dále log z aswMBR:
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-14 18:25:23
-----------------------------
18:25:23.726 OS Version: Windows x64 6.1.7601 Service Pack 1
18:25:23.726 Number of processors: 2 586 0x170A
18:25:23.742 ComputerName: ASUSG60VX UserName: jirka
18:25:24.225 Initialize success
18:25:26.530 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
18:25:26.530 Disk 0 Vendor: WDC_WD5000BPKT-75PK4T0 01.01A01 Size: 476940MB BusType: 11
18:25:26.546 Disk 1 \Device\Harddisk1\SR0 -> \Device\SdBus-0
18:25:26.546 Disk 1 Vendor: ( Size: 3780MB BusType: 12
18:25:26.639 Disk 0 MBR read successfully
18:25:26.639 Disk 0 MBR scan
18:25:26.639 Disk 0 Windows 7 default MBR code
18:25:26.639 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
18:25:26.655 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 199900 MB offset 206848
18:25:26.671 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 276937 MB offset 409602048
18:25:26.686 Disk 0 scanning C:\Windows\system32\drivers
18:25:32.037 Service scanning
18:25:43.784 Modules scanning
18:25:43.784 Disk 0 trace - called modules:
18:25:43.877 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
18:25:43.877 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c26060]
18:25:43.877 3 CLASSPNP.SYS[fffff8800189643f] -> nt!IofCallDriver -> [0xfffffa80046bb520]
18:25:43.877 5 ACPI.sys[fffff880011b37a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80046d01f0]
18:25:43.893 Scan finished successfully
18:26:01.506 Disk 0 MBR has been saved successfully to "C:\Users\jirka\Desktop\MBR.dat"
18:26:01.506 The log file has been saved successfully to "C:\Users\jirka\Desktop\aswMBR.txt"

exoslav
Level 1
Level 1
Příspěvky: 66
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod exoslav » 14 led 2014 18:31

Ten log z aswMBR je ke konci předchozího příspěvku, je to nepřehledné.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod Orcus » 14 led 2014 22:03

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

====================================================

Vyčisti systém CCleanerem

====================================================

Stáhni si zde DelFix
http://general-changelog-team.fr/fr/dow ... e/9-delfix

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem. Jinak je zpráva zde:
v C: \ DelFix.txt


Jak to vypadá s problémy?
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

exoslav
Level 1
Level 1
Příspěvky: 66
Registrován: březen 13
Pohlaví: Muž
Stav:
Offline

Re: RAnDomPirice Virus

Příspěvekod exoslav » 15 led 2014 01:46

tady je log z DELFIXU:

# DelFix v10.6 - Logfile created 15/01/2014 at 01:30:09
# Updated 11/11/2013 by Xplode
# Username : jirka - ASUSG60VX
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\AdwCleaner
Deleted : C:\Program Files (x86)\Trend Micro\Hijackthis
Deleted : C:\ComboFix.txt
Deleted : C:\Users\jirka\Desktop\aswMBR.txt
Deleted : C:\Users\jirka\Desktop\HiJackThis.lnk
Deleted : C:\Users\jirka\Desktop\MBR.dat
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
Deleted : HKLM\SYSTEM\CurrentControlSet\Services\aswMBR

~ Cleaning system restore ...

Deleted : RP #504 [ComboFix created restore point | 01/15/2014 00:06:49]

New restore point created !

########## - EOF - ##########



No, ten původní virus (RandoMPirice, ale podezřívám ho, že byl i ve složkách DoIscount) je pryč, ten jsem odstranil již předtím tuším esetem. Ale on byl poschovávaný všude možně v systému,musel jsem jednotlivé složky smazat. Byl to javascript, takže stačilo smazat zdroják, který měl, mimo jiné, nascriptováno automatické stahování pluginu do chromu, a kód tohoto viru zasíral zdroják otevřené stránky a na ní se objevovaly reklamy a nějaký další ptákoviny (už ani nevím co, ale s kódem se potom nedalo pracovat, když na jednom divu bylo idčko s názvem přes několik řádků etc.). Jestli je tam nějaký další virus, to nevím, v těch logách (nebo jak se to skloňuje) se nevyznám.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 116 hostů