- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Collect:: c:\windows\svchost.exe DDS:: uStart Page = hxxp://www.ask.com/?l=dis&o=15187 RegLock:: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] RegNull:: [HKEY_USERS\S-1-5-21-1985331280-3213936348-3091441614-1000\Software\SecuROM\License information*] Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"=- "{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"=- [-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] [-HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}] [-HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1] [-HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}] [-HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook] [-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"=- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Advanced SystemCare 5"=- "Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563] "DAEMON Tools Lite"=- "ZyngaGamesAgent"=- "SunJavaUpdateSched"=- Driver:: gupdate gupdatem File:: c:\windows\Tasks\GoogleUpdateTaskMachineCore.job c:\windows\Tasks\GoogleUpdateTaskMachineUA.job c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job Folder:: c:\program files (x86)\IObit c:\program files (x86)\Ask.com ClearJavaCache:: Replicator:: AtJob:: Reboot::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Hidrag.A
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: Hidrag.A
Re: Hidrag.A
ComboFix 12-01-30.02 - Darf 31.01.2012 16:50:39.2.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6327 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Darf\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_1638.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\IObit
c:\program files (x86)\IObit\Advanced SystemCare 5\ActiveBoost.db
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService_Log.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-15.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-16.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-17.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-18.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-19.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-20.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-21.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-22.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-23.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-24.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-25.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-26.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-27.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-28.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-29.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-30.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-31.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.tmp
c:\program files (x86)\IObit\Advanced SystemCare 5\BackupList.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2011-12-28(02-58-53).log
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-01-27(14-29-20).log
c:\program files (x86)\IObit\Advanced SystemCare 5\Ext.dbd
c:\program files (x86)\IObit\Advanced SystemCare 5\checkinfo.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.jpg
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.png
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\LatestNews.ini
c:\program files (x86)\IObit\Advanced SystemCare 5\License.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\Register.log
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2505438.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2585542.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2607576.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB915597.exe
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHoleScan.log
c:\program files (x86)\IObit\Advanced SystemCare 5\sh.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\TempResult.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\Update\Update.Ini
c:\program files (x86)\IObit\Advanced SystemCare 5\UpdateHistory.txt
c:\windows\svchost.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job
.
----- Souboroví replikátoři -----
.
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 12:04 180648 c:\windows\temp\GoogleCrashHandler.exe
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll
Wow6432Node-HKLM-Run-ApnUpdater - c:\program files (x86)\ask.com\updater\updater.exe
Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
Wow6432Node-HKLM-Run-DVAPTray - c:\windows\system32\dvaptray.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\svchost.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 16:57:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 15:57
ComboFix2.txt 2012-01-30 15:24
ComboFix3.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 305 794 441 216
Po spuštění: Volných bajtů: 306 807 357 440
.
- - End Of File - - B5FCFD25D74B897EBE79AD0ED9483547
Nahr nˇ probŘhlo ŁspŘçnŘ
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6327 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Darf\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_1638.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\IObit
c:\program files (x86)\IObit\Advanced SystemCare 5\ActiveBoost.db
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService_Log.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-15.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-16.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-17.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-18.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-19.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-20.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-21.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-22.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-23.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-24.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-25.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-26.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-27.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-28.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-29.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-30.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-31.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.tmp
c:\program files (x86)\IObit\Advanced SystemCare 5\BackupList.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2011-12-28(02-58-53).log
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-01-27(14-29-20).log
c:\program files (x86)\IObit\Advanced SystemCare 5\Ext.dbd
c:\program files (x86)\IObit\Advanced SystemCare 5\checkinfo.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.jpg
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.png
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\LatestNews.ini
c:\program files (x86)\IObit\Advanced SystemCare 5\License.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\Register.log
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2505438.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2585542.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2607576.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB915597.exe
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHoleScan.log
c:\program files (x86)\IObit\Advanced SystemCare 5\sh.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\TempResult.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\Update\Update.Ini
c:\program files (x86)\IObit\Advanced SystemCare 5\UpdateHistory.txt
c:\windows\svchost.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job
.
----- Souboroví replikátoři -----
.
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 12:04 180648 c:\windows\temp\GoogleCrashHandler.exe
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll
Wow6432Node-HKLM-Run-ApnUpdater - c:\program files (x86)\ask.com\updater\updater.exe
Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
Wow6432Node-HKLM-Run-DVAPTray - c:\windows\system32\dvaptray.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\svchost.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 16:57:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 15:57
ComboFix2.txt 2012-01-30 15:24
ComboFix3.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 305 794 441 216
Po spuštění: Volných bajtů: 306 807 357 440
.
- - End Of File - - B5FCFD25D74B897EBE79AD0ED9483547
Nahr nˇ probŘhlo ŁspŘçnŘ
Re: Hidrag.A
- Do okna vlozte skript nize
Kód: Vybrat vše
:regfind svchost.exe- Kliknete na Look
- Tlacitko Look se zmeni na Scanning a zsedne
- Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
- Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
Re: Hidrag.A
Log přesahuje max počet znaků.
nebo to hodit do několika příspěvků?
Kód: Vybrat vše
http://uloz.to/12985714/log-2-txtRe: Hidrag.A
- Rozbalte stazeny rar, tak aby byla jen jedna slozka avz4 a spustte avz.exe
- Kliknete nahore na File a nasledne vyberte Custom scripts
- Do okenka nakopirujte skript, ktery mate nize
Kód: Vybrat vše
begin SetAVZGuardStatus(True); SearchRootkit(true, true); ClearQuarantine; DeleteFile('c:\windows\svchost.exe'); BC_DeleteFile('c:\windows\svchost.exe'); StopService('PowerManager'); DeleteService('PowerManager'); RebootWindows(true); end.- Nyni kliknete na Run cimz akci spustite
- po restartu PC je mozne, ze se nacte pruvodce hardwarem, s klidem stornujte (klik na STORNO)
Re: Hidrag.A
ComboFix 12-01-30.02 - Darf 31.01.2012 19:50:43.3.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6966 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 631054 c:\windows\system32\perfh005.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
c:\program files (x86)\Ask.com\GenericAskToolbar.dll [BU]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 19:58:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 18:58
ComboFix2.txt 2012-01-31 15:58
ComboFix3.txt 2012-01-30 15:24
ComboFix4.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 306 568 650 752
Po spuštění: Volných bajtů: 306 221 404 160
.
- - End Of File - - 761658520E5F463997372203554714E3
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6966 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 631054 c:\windows\system32\perfh005.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
c:\program files (x86)\Ask.com\GenericAskToolbar.dll [BU]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 19:58:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 18:58
ComboFix2.txt 2012-01-31 15:58
ComboFix3.txt 2012-01-30 15:24
ComboFix4.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 306 568 650 752
Po spuštění: Volných bajtů: 306 221 404 160
.
- - End Of File - - 761658520E5F463997372203554714E3
Re: Hidrag.A
Skript pro SystemLook
:filefind
svchost.exe
:service
PowerManager
Re: Hidrag.A
SystemLook 30.07.11 by jpshortstuff
Log created at 20:10 on 31/01/2012 by Darf
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
========== filefind ==========
Searching for "svchost.exe"
C:\Windows\ERDNT\cache64\svchost.exe --a---- 27136 bytes [15:24 30/01/2012] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\ERDNT\cache86\svchost.exe --a---- 20992 bytes [15:24 30/01/2012] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\System32\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\SysWOW64\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe --a---- 27136 bytes [23:31 13/07/2009] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
========== service ==========
PowerManager - Unable to open Service Handle.
-= EOF =-
Log created at 20:10 on 31/01/2012 by Darf
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
========== filefind ==========
Searching for "svchost.exe"
C:\Windows\ERDNT\cache64\svchost.exe --a---- 27136 bytes [15:24 30/01/2012] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\ERDNT\cache86\svchost.exe --a---- 20992 bytes [15:24 30/01/2012] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\System32\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\SysWOW64\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe --a---- 27136 bytes [23:31 13/07/2009] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
========== service ==========
PowerManager - Unable to open Service Handle.
-= EOF =-
Re: Hidrag.A
Tak mrcha je pryc, co PC jak se chova 
Re: Hidrag.A
Bohužel AVG mi stále hlásí Hidrag.A
Re: Hidrag.A
Ona ta svine je totiz nakazila...
Zkuste pustit avptool ale na obrazku nize zaskrtnete jen Disinfect

Zkuste pustit avptool ale na obrazku nize zaskrtnete jen Disinfect
Re: Hidrag.A
Neopraví ani jediné exe které má v sobe Hidrag.a
Re: Hidrag.A
Zkuste Jeefo Removal Tool http://www.sophos.com/support/disinfection/jeefoa.html
Re: Hidrag.A
Sice to najde infikované soubory ale nedokáže je to vyléčit.



Přispějete na provoz fóra?