Log

47 views
Skip to first unread message

marian

unread,
Jul 22, 2013, 3:01:10 PM7/22/13
to virus...@googlegroups.com
Ahoj tak pre začiatok skusim log RSIT nech mam dušu na mieste či je všetko OK :)


Logfile of random's system information tool 1.09 (written by random/random)
Run by rodina at 2013-07-22 20:57:47
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 132 GB (85%) free of 155 GB
Total RAM: 1976 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:57:59, on 22. 7. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\rodina\Downloads\RSIT.exe
C:\Program Files\trend micro\rodina.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe"
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 3883 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\WpsUpdateTask_rodina.job

=========Mozilla firefox=========

ProfilePath - C:\Users\rodina\AppData\Roaming\Mozilla\Firefox\Profiles\vw5hcudy.default

"url_a...@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_a...@kaspersky.com
"virtual_...@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_...@kaspersky.com
"content...@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content...@kaspersky.com
"anti_...@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_...@kaspersky.com
"online_...@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_...@kaspersky.com


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.224 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-17 537528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2013-06-18 878784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-17 424888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-17 484280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [2013-03-15 356376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2011-02-11 171032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2011-02-11 137752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2011-02-11 172568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 1791272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-07-22 20:57:48 ----D---- C:\Program Files\trend micro
2013-07-22 20:57:47 ----D---- C:\rsit
2013-07-13 23:00:53 ----D---- C:\Windows\system32\MRT
2013-07-13 09:07:53 ----D---- C:\ProgramData\TomTom
2013-07-12 19:25:31 ----D---- C:\Users\rodina\AppData\Roaming\TomTom
2013-07-12 19:25:01 ----D---- C:\Program Files\TomTom HOME 2
2013-07-12 19:24:12 ----D---- C:\Program Files\TomTom International B.V
2013-07-10 14:37:19 ----A---- C:\Windows\system32\jscript.dll
2013-07-10 14:37:18 ----A---- C:\Windows\system32\jsproxy.dll
2013-07-10 14:37:18 ----A---- C:\Windows\system32\jscript9.dll
2013-07-10 14:37:18 ----A---- C:\Windows\system32\iesetup.dll
2013-07-10 14:37:17 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-10 14:37:17 ----A---- C:\Windows\system32\msfeeds.dll
2013-07-10 14:37:17 ----A---- C:\Windows\system32\ieui.dll
2013-07-10 14:37:17 ----A---- C:\Windows\system32\iesysprep.dll
2013-07-10 14:37:17 ----A---- C:\Windows\system32\iernonce.dll
2013-07-10 14:37:17 ----A---- C:\Windows\system32\ie4uinit.exe
2013-07-10 14:37:16 ----A---- C:\Windows\system32\urlmon.dll
2013-07-10 14:37:16 ----A---- C:\Windows\system32\iertutil.dll
2013-07-10 14:37:14 ----A---- C:\Windows\system32\wininet.dll
2013-07-10 14:37:12 ----A---- C:\Windows\system32\ieframe.dll
2013-07-10 14:37:11 ----A---- C:\Windows\system32\mshtml.dll
2013-07-10 13:25:00 ----A---- C:\Windows\system32\DWrite.dll
2013-07-10 13:24:51 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-07-10 13:24:43 ----A---- C:\Windows\system32\qedit.dll
2013-07-10 13:24:42 ----A---- C:\Windows\system32\win32k.sys
2013-07-02 12:49:30 ----AD---- C:\Windows\system32\oem
2013-07-02 12:49:26 ----D---- C:\OOBE
2013-06-30 19:42:51 ----D---- C:\ProgramData\Kingsoft
2013-06-30 19:42:29 ----D---- C:\Program Files\Kingsoft
2013-06-30 19:39:55 ----D---- C:\Users\rodina\AppData\Roaming\Kingsoft
2013-06-30 19:05:04 ----D---- C:\Users\rodina\AppData\Roaming\SoftGrid Client
2013-06-30 18:57:12 ----D---- C:\Users\rodina\AppData\Roaming\TP
2013-06-27 17:44:55 ----A---- C:\Windows\system32\msonpmon.dll
2013-06-27 17:25:04 ----RHD---- C:\MSOCache
2013-06-26 15:53:09 ----D---- C:\Program Files\Mozilla Firefox
2013-06-24 21:21:38 ----D---- C:\Program Files\Microsoft Silverlight
2013-06-24 20:50:57 ----D---- C:\Windows\pss

======List of files/folders modified in the last 1 month======

2013-07-22 20:57:59 ----D---- C:\Windows\Prefetch
2013-07-22 20:57:48 ----RD---- C:\Program Files
2013-07-22 20:30:45 ----D---- C:\Windows\Temp
2013-07-22 19:20:27 ----D---- C:\ProgramData\Kaspersky Lab
2013-07-22 18:09:14 ----D---- C:\Users\rodina\AppData\Roaming\Skype
2013-07-22 17:12:55 ----D---- C:\Windows\system32\config
2013-07-22 17:04:34 ----D---- C:\Windows\System32
2013-07-22 17:04:34 ----D---- C:\Windows\inf
2013-07-22 17:04:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-07-22 16:58:51 ----D---- C:\Windows
2013-07-21 17:36:24 ----D---- C:\Users\rodina\AppData\Roaming\vlc
2013-07-21 14:56:52 ----SD---- C:\ProgramData\Microsoft
2013-07-21 10:16:58 ----SHD---- C:\System Volume Information
2013-07-18 20:06:06 ----D---- C:\Windows\system32\catroot2
2013-07-15 19:52:21 ----D---- C:\Windows\debug
2013-07-13 09:07:53 ----HD---- C:\ProgramData
2013-07-12 21:28:01 ----SHD---- C:\Windows\Installer
2013-07-11 12:21:39 ----D---- C:\Windows\Panther
2013-07-11 11:17:00 ----D---- C:\Windows\Microsoft.NET
2013-07-11 11:16:26 ----RSD---- C:\Windows\assembly
2013-07-11 10:26:06 ----D---- C:\Windows\winsxs
2013-07-10 21:47:45 ----D---- C:\Program Files\Internet Explorer
2013-07-10 21:47:44 ----D---- C:\Program Files\Windows Journal
2013-07-10 21:47:43 ----D---- C:\Program Files\Windows Defender
2013-07-10 14:37:38 ----D---- C:\Windows\system32\catroot
2013-07-09 20:55:50 ----SD---- C:\Users\rodina\AppData\Roaming\Microsoft
2013-07-06 14:51:58 ----D---- C:\Users\rodina\AppData\Roaming\uTorrent
2013-07-05 16:18:11 ----D---- C:\Windows\Tasks
2013-07-04 22:11:47 ----D---- C:\Windows\system32\drivers\etc
2013-07-02 12:49:30 ----AD---- C:\Windows\system32\oobe
2013-06-30 19:43:59 ----D---- C:\Windows\system32\Tasks
2013-06-30 19:43:58 ----D---- C:\Windows\ShellNew
2013-06-30 19:28:02 ----D---- C:\Program Files\Common Files\microsoft shared
2013-06-30 19:28:01 ----D---- C:\Program Files\Common Files
2013-06-30 19:19:40 ----D---- C:\Windows\system32\drivers
2013-06-30 19:13:00 ----D---- C:\Program Files\Microsoft.NET
2013-06-30 19:12:32 ----RSD---- C:\Windows\Fonts
2013-06-30 19:10:44 ----D---- C:\Program Files\Common Files\System
2013-06-30 19:10:42 ----A---- C:\Windows\win.ini
2013-06-28 20:17:39 ----D---- C:\Windows\system32\drivers\UMDF
2013-06-26 19:28:19 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-06-24 00:37:58 ----A---- C:\Windows\system32\MRT.exe
2013-06-23 21:19:48 ----D---- C:\Windows\system32\wdi

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2012-06-19 136024]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2013-06-18 594528]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2012-08-02 24408]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2013-06-18 44000]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2013-06-18 145040]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2010-01-26 1163328]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2013-03-15 25944]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-03-15 25944]
R3 netr28;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28.sys [2012-12-06 2046560]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1303728]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-12-03 26112]
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [2013-03-15 356376]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2013-03-22 93072]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-19 116648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-19 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-06-26 117144]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-06-16 1343400]

-----------------EOF-----------------

Stefan Stell

unread,
Jul 22, 2013, 3:12:48 PM7/22/13
to virus...@googlegroups.com
Ahoj.
 Predsa resetni subor HOSTS, pouzi program rogueKiller, scan a potom OPRAVA hosts, HostFix.
http://www.viruskasino.com/2010/12/programy-na-odstranenie-malware-z.html#RogueKiller
Log vloz sem.

sk.m...@gmail.com

unread,
Jul 22, 2013, 3:28:54 PM7/22/13
to virus...@googlegroups.com
RogueKiller V8.6.3 [Jul 17 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operačný systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spustené v : Normálny režim
Užívateľ : rodina [Práva Správcu]
Režim : Kontrola -- Dátum : 07/22/2013 21:27:23
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy : 0 ¤¤¤

¤¤¤ Záznamy Registrov : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NÁJDENÉ
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NÁJDENÉ

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spustenie položky : 0 ¤¤¤

¤¤¤ webové prehliadače : 0 ¤¤¤

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač : [NAHRATÉ] ¤¤¤

¤¤¤ Vonkajšie Hives: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST9320325AS ATA Device +++++
--- User ---
[MBR] 5a5a932c1daa53667e78b82cf891bb22
[BSP] 156b01cba26c0b353df5ff003f9debc4 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 155146 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 317947904 | Size: 149996 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončené : << RKreport[0]_S_07222013_212723.txt >>
RKreport[0]_H_07222013_211748.txt;RKreport[0]_S_07222013_211733.txt

Stefan Stell

unread,
Jul 22, 2013, 3:43:47 PM7/22/13
to virus...@googlegroups.com
ok, v poriadku.:-D
Tot vsjo

sk.m...@gmail.com

unread,
Jul 22, 2013, 3:46:16 PM7/22/13
to virus...@googlegroups.com
Vdaka za vzhliadnutie a tvoj čas.:)

Stefan Stell

unread,
Jul 22, 2013, 3:47:02 PM7/22/13
to virus...@googlegroups.com
nemas zaco.
Reply all
Reply to author
Forward
This conversation is locked
You cannot reply and perform actions on locked conversations.
0 new messages