Obsah fóra
PravidláRegistrovaťPrihlásenie




Odpovedať na tému [ Príspevkov: 44 ] Choď na stránku: 1, 2 ďalšia
AutorSpráva
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok NapísalOffline : 13.12.2013 14:13

Prosim o pomoc skor ako sa to vsetko uplne pokazi ... asi to bude nejaky virus,pretoze sa mi sami vytvaraju rozne priecinky,takmer v kazdom priecinku sa vytvorili dalsie s tym istym nazvom, dokonca aj na novom externom hardisku :-( a z nicoho nic mi vybehol nejaky proble,nabehlo vsetko modre a nic nefungovalo, restartovala som pc a zatial ide vsetko ako tak,len sa obavam aby to neposkodilo aj to co nema ... mame vela dolezitych veci na hdd a aj v pc ...co s tym? co mam urobit?

Vopred dakujem za vsetky radi a pomoc ;-)


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 14:44

ahoj
Stiahni si RSIT z http://images.malwareremoval.com/random/RSIT.exe pre 64 bit verzie http://images.malwareremoval.com/random/RSITx64.exe spusť daj continue chvíľu počkaj dokým sa vygeneruje log keď ho vygeneruje nájdeš ho na C:\rsit\log.txt log vlož sem


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 14:50

Logfile of random's system information tool 1.09 (written by random/random)
Run by Ivana & Peter at 2013-12-13 14:45:05
Microsoft Windows 7 Ultimate
System drive C: has 679 GB (72%) free of 939 GB
Total RAM: 4095 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:45:09, on 13/12/2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Users\Ivana & Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Users\Ivana & Peter\AppData\Local\winlogon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Ivana & Peter\AppData\Local\services.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Users\Ivana & Peter\AppData\Local\lsass.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Ivana & Peter.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchesplace.info/?pi ... K&unqvl=30
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchesplace.info/?pi ... K&unqvl=30
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: savEEnashharei - {0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE} - C:\ProgramData\savEEnashharei\51ff96da0027f.dll
O2 - BHO: SearchNewTab - {3E8A11C0-6A98-6891-1311-37798D80E8AD} - C:\ProgramData\SearchNewTab\6YmMA.dll
O2 - BHO: Avira SearchFree Toolbar BHO - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro prihlášení ke službe Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" (file missing)
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Users\Ivana & Peter\AppData\Local\smss.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Ivana & Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Empty.pif = ?
O4 - Startup: Startup.exe
O4 - Global Startup: Spyder3Utility.lnk = C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
O9 - Extra button: Odoslat do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslat do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\progra~2\savesh~1\sprote~1.dll c:\progra~2\websea~1\sprote~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\nlssrv32.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Samsung AllShare PC (SamsungAllShareV2.0) - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
O23 - Service: SimpleSlideShowServer - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10941 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {E784E833-6B8F-43E3-A524-1746671C5BB4}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\nlssrv32.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1900
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9cd33318-ca72-420f-94a7-b0c16e0fabe2 -SystemEventPortName:HostProcess-1679c214-c24d-4345-83d5-60b27f6c3eec -IoCancelEventPortName:HostProcess-50d730bb-195c-4506-b7ad-aa0f78586f88 -NonStateChangingEventPortName:HostProcess-08cacda2-4f27-402d-aa13-29398fe38729 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:18dd65aa-753c-4320-94e9-6b77e4de6906
C:\Windows\servicing\TrustedInstaller.exe
"taskhost.exe"
taskeng.exe {581287F3-5EE9-4E82-AC7C-EA09F6DEB43C}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Users\Ivana & Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe"
"C:\Users\Ivana & Peter\AppData\Local\winlogon.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Users\Ivana & Peter\AppData\Local\services.exe"
"C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
"C:\Users\Ivana & Peter\AppData\Local\lsass.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 528 532 540 65536 536
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4472.0.995635112\645936204" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22,26 --gpu-vendor-id=0x10de --gpu-device-id=0x0644 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.697 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/PP_EnableZeroSuggest_R2_Stable_QueriesAndUrlsControl_NoSERP/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_76/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="4472.2.1182162167\985172858" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/PP_EnableZeroSuggest_R2_Stable_QueriesAndUrlsControl_NoSERP/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderDisabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_76/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="4472.3.605320112\2124866125" /prefetch:673131151
"C:\Users\Ivana & Peter\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\schedule!3036567561.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
Avira SearchFree Toolbar - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll [2013-10-23 13776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14 6307960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}]
savEEnashharei - C:\ProgramData\savEEnashharei\51ff96da0027f.dll [2013-08-05 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E8A11C0-6A98-6891-1311-37798D80E8AD}]
SearchNewTab - C:\ProgramData\SearchNewTab\6YmMA.dll [2012-08-05 183808]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
Avira SearchFree Toolbar - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll [2013-10-23 12240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-07-18 463272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14 4531320]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-18 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{41564952-412D-5637-00A7-7A786E7484D7} - Avira SearchFree Toolbar - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll [2013-10-23 13776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{41564952-412D-5637-00A7-7A786E7484D7} - Avira SearchFree Toolbar - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll [2013-10-23 12240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"AdobeBridge"= []
"Tok-Cirrhatus"=C:\Users\Ivana & Peter\AppData\Local\smss.exe [2009-10-15 42687]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AllShareAgent]
C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe [2012-03-01 285072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"AdobeCS5.5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]
"ApnTBMon"=C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2013-10-23 1673680]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Spyder3Utility.lnk - C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe

C:\Users\Ivana & Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Ivana & Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
Empty.pif
Startup.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2013-12-13 11:49:26 ----D---- C:\Windows\Minidump
2013-11-27 14:01:33 ----D---- C:\ProgramData\Nik Software
2013-11-27 14:01:26 ----D---- C:\Program Files\Nik Software
2013-11-21 21:27:48 ----D---- C:\Program Files\Bonjour
2013-11-21 21:27:48 ----D---- C:\Program Files (x86)\Bonjour
2013-11-17 18:49:46 ----D---- C:\Program Files (x86)\RegClean Pro
2013-11-17 18:18:24 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\Camera Bits, Inc
2013-11-17 18:14:26 ----D---- C:\Program Files (x86)\Camera Bits
2013-11-17 18:14:26 ----A---- C:\Windows\SYSWOW64\SDL.dll
2013-11-17 18:14:26 ----A---- C:\Windows\system32\SDL.dll

======List of files/folders modified in the last 1 month======

2013-12-13 14:45:07 ----D---- C:\Program Files\trend micro
2013-12-13 14:43:46 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\Dropbox
2013-12-13 14:43:37 ----D---- C:\Windows\Temp
2013-12-13 14:43:18 ----D---- C:\Windows\system32\config
2013-12-13 14:43:05 ----AD---- C:\Windows
2013-12-13 14:43:04 ----D---- C:\ProgramData\NVIDIA
2013-12-13 11:57:51 ----D---- C:\Windows\System32
2013-12-13 11:57:51 ----D---- C:\Windows\inf
2013-12-13 11:57:51 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-13 11:52:37 ----D---- C:\Windows\SoftwareDistribution
2013-12-13 11:50:20 ----D---- C:\Windows\Prefetch
2013-12-13 09:47:44 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\WinRAR
2013-12-13 09:47:44 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\tiger-k
2013-12-13 09:47:44 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\Skype
2013-12-13 09:47:39 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\FreeBurner
2013-12-13 09:46:56 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\Babylon
2013-12-13 09:21:00 ----RD---- C:\Program Files (x86)
2013-12-13 09:21:00 ----HD---- C:\ProgramData
2013-12-13 09:19:29 ----D---- C:\ProgramData\Avira
2013-12-13 09:19:28 ----D---- C:\Windows\system32\drivers
2013-12-12 20:36:07 ----D---- C:\Program Files\Common Files\Adobe
2013-12-12 20:32:45 ----D---- C:\Windows\SysWOW64
2013-12-12 20:18:51 ----SHD---- C:\System Volume Information
2013-12-05 20:27:05 ----SHD---- C:\Windows\Installer
2013-12-05 20:27:05 ----D---- C:\Config.Msi
2013-12-03 22:03:25 ----D---- C:\Windows\system32\catroot2
2013-12-03 09:30:40 ----D---- C:\Windows\system32\catroot
2013-11-27 14:01:26 ----RD---- C:\Program Files
2013-11-27 13:27:24 ----D---- C:\Program Files (x86)\Adobe
2013-11-27 13:27:11 ----D---- C:\Program Files\Adobe
2013-11-27 13:26:40 ----RSD---- C:\Windows\Fonts
2013-11-27 13:25:39 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\Adobe
2013-11-27 13:25:39 ----D---- C:\ProgramData\Adobe
2013-11-27 10:25:02 ----D---- C:\Windows\LiveKernelReports
2013-11-26 19:49:53 ----D---- C:\Program Files (x86)\Google
2013-11-26 19:49:22 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-11-21 21:30:00 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\Apple Computer
2013-11-17 18:53:17 ----D---- C:\Users\Ivana & Peter\AppData\Roaming\systweak
2013-11-17 18:45:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2012-08-24 1885792]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 48488]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 Spyder3;Datacolor Spyder3; C:\Windows\system32\DRIVERS\Spyder3.sys [2010-03-30 15360]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-09-28 53760]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 APNMCP;Ask Update Service; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-10-23 166352]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\SysWOW64\nlssrv32.exe [2012-02-27 66560]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-06 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-10 1258856]
S2 SamsungAllShareV2.0;Samsung AllShare PC; C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [2012-03-02 25504]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-06 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SimpleSlideShowServer;SimpleSlideShowServer; C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [2012-03-02 27584]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-26 257416]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2009-07-24 189728]
S4 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-05-14 3289208]
S4 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 14:53

Stiahni si USBFIX z http://www.infospyware.com/utiles/usbfix/
Zapoj USB kluče externe disky a pod
Spusť a klikni na Deletion
po skončení vybehne log budeš ho mať na C:\UsbFix.txt vlož ho sem .


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 14:57

tahujem ... a nevymaze mi to nejake dolezite veci?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 14:58

Nie nevýmaže


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 15:33

uz dost dlho to bezi,a momentalne sa to zastavilo na 52 % a pise ze mam cakat...trva to uz vyse 10minut a nic sa nedeje ... mam este cakat alebo restartovat pc?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 15:40

Sprav to teda v núdzovom režime


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 15:43

uf, a to mam ako urobit?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 15:48

uz som tam a cakam ;-)


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 16:05

je to bezne,ze treba tak dlho cakat? alebo to zasa sekne? je tam uz dost dlho 51% a pise,ze vraj scanuje,tak neviem ...


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 16:11

Dobre pôjdeme nato inač pracuj v núdzovom režime sieti
Stiahni si AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
ulož ho na plochu Spusť program stlač tlačidlo scan a následné clean
Po skene sa objaví log budeš ho mať na systémovom disku ako AdwCleanerS.txt cely obsah vlož sem

Stiahni si RKill z http://download.bleepingcomputer.com/grinler/rkill.com
ulož ho na plochu Spusť Rkill
program ukonči všetky procesi teda aj malware
Na ploche sa vytvori rkill.txt vlož ho sem
Teraz nereštartuj PC
Aplikuj hneď combofix


Stiahni si combofix z http://download.bleepingcomputer.com/sUBs/ComboFix.exe ulož ho na plochu
Vypni všetky rezidentné štíty antiviru a antyspyware
Pre WIN XP spuštaj pod administrátorom
Pre WIN Vista a WIN 7 klikny na combofix pravým tlačidlom daj spustiť ako správca
Hneď po zapnutý okno z licečnimi podmienkami stlač tlačidlo áno
Keď ty combofix ponúkne inštalovať konzolu pre zotavenie odsúhlas inštaláciu tlačidlom ANO
Behom scanu nechaj combofix pracovať nerob nič na PC
Scan môže trvať cca 10 min všetko zaleží od toho v akom stave je PC môže sa to predlžiť o dvojnásobok
Po dokončení skenovanie combofix reštartuje PC a zobrazí sa log budeš ho mať na C:\ComboFix.txt vlož ho sem
Nože sa stať že systém nenabehne v tom prípade použi poslednú známu konfiguráciu http://support.microsoft.com/kb/307852/sk


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 16:28

# AdwCleaner v3.015 - Report created 13/12/2013 at 16:19:52
# Updated 10/12/2013 by Xplode
# Operating System : Windows 7 Ultimate (64 bits)
# Username : Ivana & Peter - IAP
# Running from : C:\Users\Ivana & Peter\Desktop\Nová složka (3)\adwcleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : APNMCP

***** [ Files / Folders ] *****

File Found : C:\Windows\System32\roboot64.exe
Folder Found C:\Program Files (x86)\AskPartnerNetwork
Folder Found C:\Program Files (x86)\RegClean Pro
Folder Found C:\Program Files (x86)\SafeSaver
Folder Found C:\Program Files (x86)\WebSearch
Folder Found C:\ProgramData\apn
Folder Found C:\ProgramData\AskPartnerNetwork
Folder Found C:\ProgramData\Babylon
Folder Found C:\ProgramData\boost_interprocess
Folder Found C:\ProgramData\Browser Manager
Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\savEEnashharei
Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\savEEnashharei
Folder Found C:\ProgramData\saafe isiave
Folder Found C:\ProgramData\savEEnashharei
Folder Found C:\ProgramData\savEEnashharei
Folder Found C:\ProgramData\SearchNewTab
Folder Found C:\ProgramData\StarApp
Folder Found C:\ProgramData\Tarma Installer
Folder Found C:\Users\Ivana & Peter\AppData\Local\AskPartnerNetwork
Folder Found C:\Users\Ivana & Peter\AppData\LocalLow\Claro LTD
Folder Found C:\Users\Ivana & Peter\AppData\LocalLow\saafe isiave
Folder Found C:\Users\Ivana & Peter\AppData\LocalLow\savEEnashharei
Folder Found C:\Users\Ivana & Peter\AppData\LocalLow\savEEnashharei
Folder Found C:\Users\Ivana & Peter\AppData\LocalLow\SearchNewTab
Folder Found C:\Users\Ivana & Peter\AppData\Roaming\Babylon
Folder Found C:\Users\Ivana & Peter\AppData\Roaming\Systweak
Folder Found C:\Users\Ivana & Peter\AppData\Roaming\yourfiledownloader
Folder Found C:\Users\IVANA&~1\AppData\Local\Temp\apn
Folder Found C:\Users\IVANA&~1\AppData\Local\Temp\apn

***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\savesh~1\sprote~1.dll
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\websea~1\sprote~1.dll
Key Found : HKCU\Software\a53de8ce13be410
Key Found : HKCU\Software\AppDataLow\SProtector
Key Found : HKCU\Software\AskPartnerNetwork
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41564952-412D-5637-00A7-7A786E7484D7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{589697B7-A071-2BD1-2577-6A234FCFE56E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41564952-412D-5637-00A7-7A786E7484D7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{589697B7-A071-2BD1-2577-6A234FCFE56E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\systweak
Key Found : HKCU\Software\YourFileDownloader
Key Found : [x64] HKCU\Software\AskPartnerNetwork
Key Found : [x64] HKCU\Software\DataMngr
Key Found : [x64] HKCU\Software\DataMngr_Toolbar
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\systweak
Key Found : [x64] HKCU\Software\YourFileDownloader
Key Found : HKLM\Software\AskPartnerNetwork
Key Found : HKLM\Software\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\SearchNewTab.SearchNewTab
Key Found : HKLM\SOFTWARE\Classes\SearchNewTab.SearchNewTab.1.0
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_cool-mkv-to-mp4-converter_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_cool-mkv-to-mp4-converter_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_mkv-player_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_mkv-player_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_703c874a
Key Found : HKLM\Software\SearchquSRTB
Key Found : HKLM\Software\SP Global
Key Found : HKLM\Software\SProtector
Key Found : HKLM\Software\YourFileDownloader
Key Found : [x64] HKLM\SOFTWARE\AskPartnerNetwork
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : [x64] HKLM\SOFTWARE\DataMngr
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : [x64] HKLM\SOFTWARE\Speedchecker Limited
Key Found : [x64] HKLM\SOFTWARE\Tarma Installer
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{41564952-412D-5637-00A7-7A786E7484D7}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Value Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}]

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7600.16385

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://websearch.searchesplace.info/?pi ... K&unqvl=30
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://websearch.searchesplace.info/?pi ... K&unqvl=30

-\\ Mozilla Firefox v

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Ivana & Peter\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [13171 octets] - [13/12/2013 16:19:52]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [13232 octets] ##########






# AdwCleaner v3.015 - Report created 13/12/2013 at 16:21:45
# Updated 10/12/2013 by Xplode
# Operating System : Windows 7 Ultimate (64 bits)
# Username : Ivana & Peter - IAP
# Running from : C:\Users\Ivana & Peter\Desktop\Nová složka (3)\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : APNMCP

***** [ Files / Folders ] *****

[!] Folder Deleted : C:\ProgramData\apn
[!] Folder Deleted : C:\ProgramData\AskPartnerNetwork
[!] Folder Deleted : C:\ProgramData\Babylon
[!] Folder Deleted : C:\ProgramData\boost_interprocess
[!] Folder Deleted : C:\ProgramData\Browser Manager
[!] Folder Deleted : C:\ProgramData\StarApp
[!] Folder Deleted : C:\ProgramData\Tarma Installer
[!] Folder Deleted : C:\ProgramData\saafe isiave
[!] Folder Deleted : C:\ProgramData\savEEnashharei
[!] Folder Deleted : C:\ProgramData\savEEnashharei
[!] Folder Deleted : C:\ProgramData\SearchNewTab
[!] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\savEEnashharei
[!] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\savEEnashharei
[!] Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
[!] Folder Deleted : C:\Program Files (x86)\RegClean Pro
[!] Folder Deleted : C:\Program Files (x86)\SafeSaver
[!] Folder Deleted : C:\Program Files (x86)\WebSearch
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\Local\AskPartnerNetwork
[!] Folder Deleted : C:\Users\IVANA&~1\AppData\Local\Temp\apn
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\LocalLow\Claro LTD
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\LocalLow\saafe isiave
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\LocalLow\savEEnashharei
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\LocalLow\savEEnashharei
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\LocalLow\SearchNewTab
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\Roaming\Babylon
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\Roaming\Systweak
[!] Folder Deleted : C:\Users\Ivana & Peter\AppData\Roaming\yourfiledownloader
[!] Folder Deleted : C:\Users\IVANA&~1\AppData\Local\Temp\apn
File Deleted : C:\Windows\System32\roboot64.exe

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\SearchNewTab.SearchNewTab
Key Deleted : HKLM\SOFTWARE\Classes\SearchNewTab.SearchNewTab.1.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_703c874a
Key Deleted : HKCU\Software\a53de8ce13be410
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_cool-mkv-to-mp4-converter_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_cool-mkv-to-mp4-converter_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_mkv-player_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_mkv-player_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{589697B7-A071-2BD1-2577-6A234FCFE56E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{589697B7-A071-2BD1-2577-6A234FCFE56E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0C96462A-7BC5-7BF0-92AB-BB8C0C5496DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E8A11C0-6A98-6891-1311-37798D80E8AD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{41564952-412D-5637-00A7-7A786E7484D7}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\YourFileDownloader
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKLM\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\SearchquSRTB
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\Software\YourFileDownloader
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}
Key Deleted : [x64] HKLM\SOFTWARE\AskPartnerNetwork
Key Deleted : [x64] HKLM\SOFTWARE\DataMngr
Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\savesh~1\sprote~1.dll
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\websea~1\sprote~1.dll

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7600.16385

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Ivana & Peter\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [13409 octets] - [13/12/2013 16:19:52]
AdwCleaner[S0].txt - [12386 octets] - [13/12/2013 16:21:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12447 octets] ##########


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 16:31

Rkill 2.6.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 12/13/2013 04:30:08 PM in x64 mode. (Safe Mode)
Windows Version: Windows 7 Ultimate

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
C:\Users\Ivana & Peter\Desktop\rkill\rkill-12-13-2013-04-30-09.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* Systém událostí COM+ (EventSystem) is not Running.
Startup Type set to: Automatic

* Centrum zabezpečení (wscsvc) is not Running.
Startup Type set to: Automatic (Delayed Start)

* Windows Update (wuauserv) is not Running.
Startup Type set to: Automatic (Delayed Start)

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 adobe.activate.com
127.0.0.1 adobeereg.com
127.0.0.1 www.adobeereg.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 125.252.224.90
127.0.0.1 125.252.224.91

20 out of 21 HOSTS entries shown.
Please review HOSTS file for further entries.

Program finished at: 12/13/2013 04:31:07 PM
Execution time: 0 hours(s), 0 minute(s), and 59 seconds(s)


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 17:00

combofix asi seklo :-( prve tri isli v pohode a teraz sa nic nedeje ... mam to vypnut a skusit urobit znova?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 17:07

Skus to spraviť znova premenuj combofix na 123 a spusť


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 17:16

nic ... to iste ako predtym :( mozem urobit nieco ine? a zistil si nieco v tym log-och predtym?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 17:35

Stiahni MBAR http://www.bleepingcomputer.com/downloa ... i-rootkit/
Ulož na plochu a rozbaľ spusti kliknutím na mbar
Teraz daj next a update
Po skončení aktualizácie klikni na next
zaškrtni všetky tri možnosti a stlač scan
Po skončení skenu zaškrtni všetky nálezy teraz môžeš stlačiť CleanUp
PC sa reštartuje V zložke MBAR nájdeš log ten sem vlož


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 18:41

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1008

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7600 Windows 7 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 8.0.7600.16385

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, J:\ DRIVE_FIXED, K:\ DRIVE_FIXED
CPU speed: 2.333000 GHz
Memory total: 4294156288, free: 3455041536

No address found
No address found
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1008

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7600 Windows 7 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 8.0.7600.16385

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, J:\ DRIVE_FIXED, K:\ DRIVE_FIXED
CPU speed: 2.333000 GHz
Memory total: 4294156288, free: 3594219520

Downloaded database version: v2013.12.13.05
Downloaded database version: v2013.10.11.02
=======================================
Initializing...
------------ Kernel report ------------
12/13/2013 17:42:45
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\DRIVERS\ACPI.sys
\SystemRoot\system32\DRIVERS\WMILIB.SYS
\SystemRoot\system32\DRIVERS\msisadrv.sys
\SystemRoot\system32\DRIVERS\pci.sys
\SystemRoot\system32\DRIVERS\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStorV.sys
\SystemRoot\system32\DRIVERS\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\vmstorfl.sys
\SystemRoot\system32\DRIVERS\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\netr28x.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\DRIVERS\1394ohci.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStorV.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\framebuf.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\ole32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\wininet.dll
\Windows\System32\nsi.dll
\Windows\System32\sechost.dll
\Windows\System32\kernel32.dll
\Windows\System32\user32.dll
\Windows\System32\clbcatq.dll
\Windows\System32\oleaut32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\difxapi.dll
\Windows\System32\advapi32.dll
\Windows\System32\psapi.dll
\Windows\System32\shlwapi.dll
\Windows\System32\urlmon.dll
\Windows\System32\msvcrt.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\normaliz.dll
\Windows\System32\usp10.dll
\Windows\System32\ws2_32.dll
\Windows\System32\gdi32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\msctf.dll
\Windows\System32\iertutil.dll
\Windows\System32\shell32.dll
\Windows\System32\lpk.dll
\Windows\System32\setupapi.dll
\Windows\System32\imm32.dll
\Windows\System32\crypt32.dll
\Windows\System32\wintrust.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\devobj.dll
\Windows\System32\KernelBase.dll
\Windows\System32\comctl32.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk6\DR6
Upper Device Object: 0xfffffa8006b96060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000007e\
Lower Device Object: 0xfffffa8006b8f760
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk5\DR5
Upper Device Object: 0xfffffa8006b95060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000007d\
Lower Device Object: 0xfffffa8006b7c060
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR4
Upper Device Object: 0xfffffa8006b94060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000007c\
Lower Device Object: 0xfffffa8006b88060
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR3
Upper Device Object: 0xfffffa8006b93060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000007b\
Lower Device Object: 0xfffffa8006b81060
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR2
Upper Device Object: 0xfffffa8006b41790
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000072\
Lower Device Object: 0xfffffa8006b3b3c0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa8005eb82d0
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000066\
Lower Device Object: 0xfffffa8005ec56a0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa800554e060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa8004f5c050
Lower Device Driver Name: \Driver\iaStorV\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800554e060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80054458c0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800554e060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8004f5c050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStorV\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: C6ABA24

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 1923987393
Partition file system is NTFS
Partition is bootable

Partition 1 type is Other (0xc)
Partition is NOT ACTIVE.
Partition starts at LBA: 1923987456 Numsec = 29534208

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-1953505168-1953525168)...
Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa8005eb82d0, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8005ebb6f0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8005eb82d0, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8005ec56a0, DeviceName: \Device\00000066\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 5F107

Partition information:

Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 2048 Numsec = 3906961408

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 2000365289472 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 512
Drive: 2, DevicePointer: 0xfffffa8006b41790, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8006b53630, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8006b41790, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006b3b3c0, DeviceName: \Device\00000072\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 2
Scanning MBR on drive 2...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: CB4A53FB

Partition information:

Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 976768002

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 500107862016 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xfffffa8006b93060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8006b89040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8006b93060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006b81060, DeviceName: \Device\0000007b\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xfffffa8006b94060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8006b8f040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8006b94060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006b88060, DeviceName: \Device\0000007c\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 5, DevicePointer: 0xfffffa8006b95060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8006b93b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8006b95060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006b7c060, DeviceName: \Device\0000007d\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 6, DevicePointer: 0xfffffa8006b96060, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8006b94b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8006b96060, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006b8f760, DeviceName: \Device\0000007e\, DriverName: \Driver\USBSTOR\
------------ End ----------
Infected: C:\Users\Ivana & Peter\AppData\Local\smss.exe --> [Trojan.Dropper]
Infected: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Tok-Cirrhatus --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Roaming.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\Adobe Mini Bridge CS6\Adobe Mini Bridge CS6.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\AIR\AIR.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\Extension Manager CS5\Extension Manager CS5.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\Extension Manager CS5.5\Extension Manager CS5.5`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\LogTransport2\LogTransport2.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\SwitchBoard\SwitchBoard.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\Bridge CS6\Bridge CS6.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\CameraRaw\CameraRaw.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\Color\Color.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Adobe\Common\Common.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Apple Computer\Logs\Logs.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Apple Computer\Preferences\Preferences.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Apple Computer\Safari\Safari.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Camera Bits, Inc\Photo Mechanic\Photo Mechanic.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1\Local Store\Local Store.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\com.dwuser.erwizard.EasyRotatorWizard\Local Store\Local Store.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\CyberLink\CLB\CLB.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Dropbox\Dropbox.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Dropbox\bin\bin.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Dropbox\l\l.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\FreeBurner\FreeBurner.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Leawo\Video Converter\Video Converter.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Microsoft\Office\Office.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Microsoft\Protect\Protect.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Microsoft\UProof\UProof.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Microsoft\Šablóny\Šablóny.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\NVIDIA\ComputeCache\ComputeCache.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Opera\Opera\Opera.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\PACE Anti-Piracy\0g9BEKZLn3b\0g9BEKZLn3b.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\PACE Anti-Piracy\1yQEQTKmWfuo1v8\1yQEQTKmWfuo1v8.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Samsung\AllShare\AllShare.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Skype\Skype.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Skype\nanka295\nanka295.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Skype\photopeter1\photopeter1.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Skype\shared_dynco\shared_dynco.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Skype\shared_httpfe\shared_httpfe.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\tiger-k\tiger-k.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\WindSolutions\CopyTrans\CopyTrans.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\WindSolutions\CopyTransDriversInstaller\CopyTransDriversInstaller.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\WindSolutions\CopyTransManager\CopyTransManager.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\WindSolutions\CopyTransPhoto\CopyTransPhoto.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\WinRAR\WinRAR.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Desktop.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Windows.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\1029\1029.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Caches\Caches.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Explorer\Explorer.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\History\History.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Temporary Internet Files.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Themes\Themes.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Startup.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Temp\Temp.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Temp\AdobeDownload\AdobeDownload.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Temp\4700_4941\4700_4941.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Ivana & Peter.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Contacts\Contacts.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Documents\Documents.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Downloads\Downloads.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Favorites\Favorites.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Links\Links.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Music\Music.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Pictures\Pictures.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Saved Games\Saved Games.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Searches\Searches.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Videos\Videos.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Public.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Documents\Documents.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Downloads\Downloads.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Libraries\Libraries.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Music\Hudba.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Music\Music.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Music\My Music.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Pictures\My Pictures.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Pictures\Obrázky.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Pictures\Pictures.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Recorded TV\Recorded TV.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Videos\Filmy.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Videos\My Videos.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Videos\Videos.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\csrss.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\inetinfo.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Local.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\lsass.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\services.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\winlogon.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Nik Software\Color Efex Pro 4\Color Efex Pro 4.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Nik Software\Silver Efex Pro 2\Silver Efex Pro 2.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Adobe\Color\Color.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Adobe\OOBE\OOBE.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Apple Computer\Safari\Safari.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\CaptureOne\CaptureOne.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\CaptureOne\CustomCommands\CustomCommands.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\CaptureOne\Logs\Logs.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\CaptureOne\Recipes\Recipes.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Datacolor\Spyder3Elite\Spyder3Elite.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Datacolor\Spyder3Pro\Spyder3Pro.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Datacolor\Spyder3Utility\Spyder3Utility.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Downloaded Installations\{C15E23CB-2AA0-4C62-BB3E-BBC958B763B4}\{C15E23CB-2AA0-4C62-BB3E-BBC958B763B4}.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\g9BEKZLn3\g9BEKZLn3.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Google\Custom Buttons\Custom Buttons.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\HF Designer\{23700CFA-271F-437F-944F-97980B730D9F}\{23700CFA-271F-437F-944F-97980B730D9F}.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\iOXPdjuKZvFR\iOXPdjuKZvFR.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Loc.Mail.Bron.Tok\Loc.Mail.Bron.Tok`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Credentials\Credentials.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Device Metadata\Device Metadata.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Feeds\Feeds.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\FORMS\FORMS.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Internet Explorer\Internet Explorer.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Media Player\Media Player.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Outlook\Outlook.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows Mail\Windows Mail.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows Sidebar\Windows Sidebar.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Opera\Opera\Opera.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Music\Sample Music\Sample Music.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Pictures\Sample Pictures\Sample Pictures.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Recorded TV\Sample Media\Sample Media.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Recorded TV\TempRec\TempRec.exe --> [Trojan.Dropper]
Infected: C:\Users\Public\Videos\Sample Videos\Sample Videos.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe Premiere Pro CS5.5`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe CS5.5\Adobe CS5.5`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe CS5.5\deploy\deploy.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe CS5.5\packages\packages.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe CS5.5\payloads\payloads.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe CS5.5\resources\resources.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe Encore CS5.1\Adobe Encore CS5.1`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe OnLocation CS5.1\Deutsch\Deutsch.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe OnLocation CS5.1\English\English.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe OnLocation CS5.1\Español\Español.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe OnLocation CS5.1\Français\Français.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Adobe Premiere Pro CS5.5\Adobe OnLocation CS5.1\Italiano\Italiano.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\capture one\capture one.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\capture one\Capture.One.PRO.v6.4.56957_Snorgared\Capture.One.PRO.v6.4.56957_Snorgared`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\capture one\Capture.One.PRO.v6.4.56957_Snorgared\eatc6401\eatc6401.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\pokus10\pokus10.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\pokus10\picslideshow\picslideshow.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\pokus3\pokus3.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\pokus3\css\css.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\pokus3\icons\icons.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\pokus3\images\images.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\pokus3\js\js.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\premiere pro\premiere pro.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\premiere pro\Adobe.Premiere.Pro.CS5.5.v5.5.x64.Multilenguaje. Final Full by JHEANFRANCO\Adobe.Premiere.Pro.CS5.5.v5.5.x64.Multilenguaje. Final Full by JHEANFRANCO`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\premiere pro\Adobe.Premiere.Pro.CS5.5.v5.5.x64.Multilenguaje. Final Full by JHEANFRANCO\crack by JheanFranco\crack by JheanFranco.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\premiere pro\Adobe.Premiere.Pro.CS5.5.v5.5.x64.Multilenguaje. Final Full by JHEANFRANCO\crack by JheanFranco\keygen.exe --> [Trojan.Agent.CK]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Gratulácie\Gratulácie.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Hostina\Hostina.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Kadernícke a kozmetické prípravy\Kadernícke a kozmetické prípravy.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Obliekanie a pripravy Bou\Obliekanie a pripravy Bou.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Obliekanie a pripravy u Katky\Obliekanie a pripravy u Katky.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Obrad\Obrad.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Odpytávanie\Odpytávanie.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\RETOUCHED\RETOUCHED.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\RETOUCHED-WEB SIZE\RETOUCHED-WEB SIZE.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\FINAL\Štylizované fotenie\Štylizované fotenie.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Gratulácie\Gratulácie.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Hostina\Hostina.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Kadernícke a kozmetické prípravy\Kadernícke a kozmetické prípravy.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Obliekanie a pripravy Bou\Obliekanie a pripravy Bou.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Obliekanie a pripravy u Katky\Obliekanie a pripravy u Katky.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Obrad\Obrad.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Odpytávanie\Odpytávanie.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Katka a Bou 16.11.2013\Štylizované fotenie\Štylizované fotenie.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\mum & son\mum & son.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\my na ranci\my na ranci.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\nela a lucky\nela a lucky.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\nevesta.sk\nevesta.sk`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\nevesta.sk\Nová složka\Nová složka.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\nevesta.sk\Nová složka\deti\deti.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\nevesta.sk\Nová složka\rande\rande.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\nevesta.sk\Nová složka\svadobne\svadobne.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka\Nová složka.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Dropbox\Dropbox.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Dropbox\Camera Uploads\Camera Uploads.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\Fashion Miska.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\CaptureOne\Settings50\Settings50.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\FINAL\FINAL.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\FINAL\Portretove fotenie\Portretove fotenie.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\FINAL\RETOUCHED\RETOUCHED.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\FINAL\RETOUCHED-WEB SIZE\RETOUCHED-WEB SIZE.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\retouched\retouched.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\retouched\RETOUCHED\RETOUCHED.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Fashion Miska\retouched\RETOUCHED-WEB SIZE\RETOUCHED-WEB SIZE.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\florabella_spring_actions\florabella_spring_actions.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\florabella_spring_actions\BrownieActionBYalinalovato\BrownieActionBYalinalovato.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\florabella_spring_actions\photoshop_orangetones_action_by_lieveheersbeestje\photoshop_orangetones_action_by_lieveheersbeestje.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\florabella_spring_actions\Wonderland Action\Wonderland Action.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\SONGS FROM IPHONE\SONGS FROM IPHONE.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Tatiana a Rocco\Tatiana a Rocco.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Tatiana a Rocco\FINAL\RETOUCHED\RETOUCHED.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Tatiana a Rocco\FINAL\RETOUCHED-WEB SIZE\RETOUCHED-WEB SIZE.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\USB.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\jquery-lightbox-0.5\jquery-lightbox-0.5`.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\jquery-lightbox-0.5\css\css.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\jquery-lightbox-0.5\images\images.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\jquery-lightbox-0.5\js\js.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\jquery-lightbox-0.5\photos\photos.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\Adobe Dreamweaver CS5\Adobe Dreamweaver CS5.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\Adobe Dreamweaver CS5\Adobe Dreamweaver CS5\Adobe Dreamweaver CS5.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\Fonts\Fonts.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\USB\images\images.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\usb2\usb2.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\usb2\oznamenia k+j\oznamenia k+j.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\usb2\pokus10\pokus10.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\usb2\pokus10\imagessss\imagessss.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Viky, Timi a Tobi\Viky, Timi a Tobi.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Viky, Timi a Tobi\FINAL\FINAL.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Viky, Timi a Tobi\FINAL\RETOUCHED\RETOUCHED.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Viky, Timi a Tobi\FINAL\RETOUCHED-WEB SIZE\RETOUCHED-WEB SIZE.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\web.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\Imageees\Imageees.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\imagessss\imagessss.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\resources\resources.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\resources\javascript\javascript.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\resources\localization\localization.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\resources\mediaGroupData\mediaGroupData.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\resources\styles\styles.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\web\Templates\Templates.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\Nová složka (2).exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\boot\boot.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\boot\cs-cz\cs-cz.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\boot\fonts\fonts.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\sources\sources.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\sources\cs-cz\cs-cz.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\sources\dlmanifests\dlmanifests.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\sources\etwproviders\etwproviders.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\sources\inf\inf.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\sources\replacementmanifests\replacementmanifests.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\sources\servicingstackmisc\servicingstackmisc.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\support\logging\logging.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\support\migwiz\migwiz.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\support\tools\tools.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Nová složka (2)\upgrade\netfx\netfx.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\PROG\PROG.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\gangster wedding style\gangster wedding style.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\gangster wedding style\autumn\autumn.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\Desktop\Have to GO there Podersdorf am See\Have to GO there Podersdorf am See.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\31VTSKPF\31VTSKPF.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9TS5T0OA\9TS5T0OA.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9TVL82F4\9TVL82F4.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E52FR3ZL\E52FR3ZL.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LKJUAT97\LKJUAT97.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M2GM8OBK\M2GM8OBK.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OWIVJ8A7\OWIVJ8A7.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RO76UQ52\RO76UQ52.exe --> [Trojan.Dropper]
Infected: C:\Users\Ivana & Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Content.IE5`.exe --> [Trojan.Dropper]
Infected: C:\Windows\eksplorasi.exe --> [Backdoor.Bot]
Infected: C:\Windows\ShellNew\sempalong.exe --> [Worm.Brontok]
Infected: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoFolderOptions --> [Hijack.FolderOptions]
Infected: HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Bron-Spizaetus --> [Worm.Brontok]
Infected: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM|disableregistrytools --> [PUM.Hijack.Regedit]
Infected: HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON|Shell --> [Hijack.Shell]
Scan finished
Creating System Restore point...
Could not create restore point...
Cleaning up...
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 13.12.2013 18:42

a co teraz?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 13.12.2013 19:05

Stiahni si MBAM z http://www.techspot.com/downloads/4716- ... lware.html nainštaluj spusť daj plnú kontrolu zmaž nájdene pošli výpis z protokolov


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 14.12.2013 0:00

mam hotovy log ale je prilis velky a dlhy a nechce mi to tu vlozit ... ako inac to poslem? alebo to mam dat do rar suboru a hodit na nejaky server?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 14.12.2013 0:04

Skus http://leteckaposta.cz/ a daj toho link


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 14.12.2013 9:34

http://leteckaposta.cz/475121456


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 14.12.2013 10:18

Stiahni si kaspersky virus removal tool verziu 11 http://www.kaspersky.com/antivirus-removal-tool?form=1
Spusť inštalátor daj pokračovať.Následne sa zobrazia licenčne podmienky zvoľ možnosť I accept the lincense agreement a stlač tlačidlo start
Následne sa zobrazí hlavné okno programu stlač tlačidlo ozubeného kolesa v záložke scan zaškrtni System memory,Hidden startup objects,Disk boot sectors, Dokumenty, My email,Tento počítač, Disk C: a všetky ostatne disky ktoré sú v možnosti aj externe zariadenia.
Teraz stlač na záložku Actions, vyber možnosť select action zaškrtni možnosti Disinfect a Delete if disinfection fails
Klikni na Automatic scan Zobrazí sa ty tlačidlo Start scanning stlač ho PC sa teraz začne kontrola
Po dokončení kontroly klikni na ikonu s poznámkami následne stlač záložku Detected threats. Následne klikni na tlačidlo save. Názov súboru daj LOG a ulož súbor na plochu následné súbor daj na http://leteckaposta.cz/ a vlož link.


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 03.01.09
Príspevky: 10120
Témy: 8
Bydlisko: KE
Príspevok NapísalOffline : 14.12.2013 10:48

Aj keď sa podartí takýmto spôsobom vyliešiť chorý OS aj tak je to podľa mňa o ničom.Nikdy to nebude na 100% .Už dávno by som bol stiahol potrebné dáta z HDD a nainštaloval OS min. na 20 PC.Treba to však dať tomu kto sa tomu rozumie ,nemyslím na "personal compuper " ale takému kto bude fyzický pri tom PC pretože tak sa s PC lepšie pracuje.Ale nech sa vám darí ,prajem pekný víkend.







_________________
PC MB:ASUS Sabertooth P67 CPU:i5-3570S+cooler GEMIN II SF524 RAM:Kingston HyperX BEAST XMP 4x4GB 1866MHz GPU:MSI N750Ti-2GD5/OC
SSD1:
Samsung 850Pro 256GB SSD2:WD Blue 1TB SSD3: Crucial MX500 2TB SSD4:Kingston DC600M 1,92TB SSD5:WD RED SA500 4TB SSD6:WD RED SA500 4TB SSD7:Samsung 970 EVO PLUS 2TB
PSU:
Be quiet! Straight Power 11 650WCASE:CoolerMaster CMForce 500 LCD:Dell S2721DGF
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 15.12.2013 10:28

http://leteckaposta.cz/112279489


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 15.12.2013 11:53

Dobre pokračuj combofixom


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 25.01.11
Prihlásený: 06.03.16
Príspevky: 37
Témy: 5
Príspevok Napísal autor témyOffline : 15.12.2013 12:22

Combofix neide...vzdy sa zasekne po ''Completed Stage_3'' :-(


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 15.12.2013 15:29

Combofix premenuj na uninstall a spusť
Na adwclener zvoľ možnosť uninstall
vlož novy Log z rsit


Odpovedať na tému [ Príspevkov: 44 ] Choď na stránku: 1, 2 ďalšia


Podobné témy

 Témy  Odpovede  Zobrazenia  Posledný príspevok 
V tomto fóre nie sú ďalšie neprečítané témy. pomoc pomoc prosim nefunguje internet

v Ovládače

7

1141

09.09.2017 20:37

Smith Wesson Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosim POMOC!

[ Choď na stránku:Choď na stránku: 1, 2 ]

v Procesory

34

2047

09.11.2008 10:32

pukepulos Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. PROSIM POMOC

v Antivíry a antispywary

11

1486

18.05.2008 17:53

br4n0 Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosím pomoc

v Operačné systémy Microsoft

8

529

20.11.2008 15:47

snow23 Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosim o pomoc

v Antivíry a antispywary

1

592

09.03.2008 17:47

yaJohny Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. prosím o pomoc

v Video programy

2

636

03.03.2010 10:42

BuchtosG Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. prosim pomoc surne

v AMD - Advanced Micro Devices

2

738

16.05.2007 19:13

raddo Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosim o pomoc

v Ostatné programy

7

724

19.05.2008 13:51

shiro Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. prosím o pomoc

v Grafické programy

1

242

23.03.2014 16:09

shiro Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosim o pomoc!!

v ATI/AMD grafické karty

22

1341

30.01.2008 21:23

Jaro Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. torent prosim pomoc

v Sieťové a internetové programy

4

500

22.02.2009 21:37

Atrix24 Zobrazenie posledných príspevkov

Táto téma je zamknutá, nemôžete posielať nové príspevky alebo odpovedať na staršie. prosim o pomoc

v nVidia grafické karty

1

358

02.10.2010 11:24

Ďuri Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. prosím o pomoc :(

v HTML, XHTML, XML, CSS

5

620

18.03.2008 16:52

emer Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. prosim o pomoc

v Ostatné

5

613

16.12.2007 20:41

Daron Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. prosim o pomoc

v Audio programy

1

579

14.07.2009 19:49

psichac Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. prosím o pomoc

v Antivíry a antispywary

8

703

05.02.2008 9:05

biba5 Zobrazenie posledných príspevkov


Nemôžete zakladať nové témy v tomto fóre
Nemôžete odpovedať na témy v tomto fóre
Nemôžete upravovať svoje príspevky v tomto fóre
Nemôžete mazať svoje príspevky v tomto fóre

Skočiť na:  

Powered by phpBB Jarvis © 2005 - 2024 PCforum, webhosting by WebSupport, secured by GeoTrust, edited by JanoF
Ako väčšina webových stránok aj my používame cookies. Zotrvaním na webovej stránke súhlasíte, že ich môžeme používať.
Všeobecné podmienky, spracovanie osobných údajov a pravidlá fóra