Ahoj
Potřebuji se toho šmejda nějak zbavit. Systém funguje jen v nouzovém režimu s prací v síti. Prozatím jsem spustil kompletní scan v McAfee....
Díky za pomoc.
Edit:
rkill log:
Rkill 2.3.15 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 09/15/2012 01:53:09 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\Tom\Desktop\rkill\rkill-09-15-2012-01-53-29.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Defender Disabled
[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001
Checking Windows Service Integrity:
* Systém událostí COM+ (EventSystem) is not Running.
Startup Type set to: Manual
* Centrum zabezpečení (wscsvc) is not Running.
Startup Type set to: Disabled
* Windows Update (wuauserv) is not Running.
Startup Type set to: Disabled
Searching for Missing Digital Signatures:
* No issues found.
Program finished at: 09/15/2012 01:53:40 PM
Execution time: 0 hours(s), 0 minute(s), and 31 seconds(s)
Live security platinum - EDIT: prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Live security platinum - EDIT: prosím o kontrolu logu
Naposledy upravil(a) fajla99 dne 15 Zář 2012 14:04, celkem upraveno 1 x.
Re: Live security platinum
Tak jsem to projel ještě combofixem, kterej toho šmejda smazal....
Tady je LOG:
ComboFix 12-09-14.03 - Tom 15.09.2012 14:12:34.2.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3998.2882 [GMT 2:00]
Spuštěný z: c:\users\Tom\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\users\Public\AlexaNSISPlugin.2688.dll
c:\users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum
c:\users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum\Live Security Platinum.lnk
c:\windows\SysWow64\muzapp.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 12:16 . 2012-09-15 12:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-15 12:00 . 2012-09-15 12:01 -------- d-----w- c:\program files\trend micro
2012-09-15 12:00 . 2012-09-15 12:01 -------- d-----w- C:\rsit
2012-09-15 11:24 . 2012-09-15 11:49 -------- d-----w- c:\programdata\7531CCCB00011628005484B8F875F002
2012-09-14 23:04 . 2012-09-14 23:04 -------- d-----w- c:\programdata\RELOADED
2012-09-14 22:58 . 2012-09-14 23:04 -------- d-----w- c:\program files (x86)\The Walking Dead Episode 3
2012-09-14 22:48 . 2012-09-14 22:48 -------- d-----w- c:\program files (x86)\Telltale Games
2012-09-14 22:09 . 2010-06-02 02:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2012-09-14 22:09 . 2010-06-02 02:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2012-09-14 21:53 . 2012-09-15 11:26 -------- d-----w- c:\program files (x86)\Rage
2012-09-14 21:52 . 2012-09-14 22:11 -------- d-sh--w- c:\windows\ei_temp
2012-09-14 21:41 . 2012-09-14 21:41 -------- d-----w- c:\program files (x86)\The Walking Dead
2012-09-14 20:57 . 2012-09-14 20:57 -------- d-----w- C:\Fraps
2012-09-14 20:48 . 2012-09-14 20:48 1998168 ----a-w- c:\windows\SysWow64\d3dx9_43.dll
2012-09-14 20:44 . 2006-03-31 10:40 352464 ----a-w- c:\windows\system32\xactengine2_1.dll
2012-09-14 20:43 . 2012-09-14 20:43 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2012-09-14 20:29 . 2010-11-11 10:46 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2012-09-14 20:29 . 2012-09-14 20:29 2106216 ----a-w- c:\windows\SysWow64\d3dcompiler_43.dll
2012-09-14 20:28 . 2012-09-14 20:37 -------- d-----w- c:\program files (x86)\Dll-Files.com Fixer
2012-09-14 20:28 . 2012-09-14 20:27 3799904 ----a-w- c:\windows\system32\dffsetup-d3dcompiler_43.exe
2012-09-14 19:31 . 2012-09-14 19:31 -------- d-----w- c:\program files (x86)\THQ
2012-09-14 18:28 . 2012-09-14 18:28 -------- d-----w- c:\program files (x86)\PANDORA.TV
2012-09-14 18:28 . 2012-09-14 23:21 -------- d-----w- c:\program files (x86)\The KMPlayer
2012-09-14 18:27 . 2012-09-14 18:27 -------- d-----w- c:\programdata\Ask
2012-09-14 17:54 . 2012-09-14 22:15 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-09-14 17:54 . 2012-09-14 17:55 -------- d-----w- c:\programdata\Blizzard Entertainment
2012-09-14 17:53 . 2012-09-14 17:54 -------- d-----w- c:\programdata\Battle.net
2012-09-14 17:40 . 2012-09-14 17:40 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-09-14 17:40 . 2012-09-14 17:40 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-09-14 17:38 . 2012-09-14 17:43 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-09-14 05:37 . 2012-09-14 06:36 -------- d-----w- C:\totalcmd
2012-09-13 23:19 . 2012-09-13 23:19 -------- d-----w- C:\AllShare
2012-09-13 22:23 . 2012-09-13 22:23 -------- d-----w- c:\program files (x86)\Common Files\Wondershare
2012-09-13 22:23 . 2012-09-13 22:23 -------- d-----w- c:\program files (x86)\Wondershare
2012-09-13 21:22 . 2012-07-31 10:42 203104 ----a-w- c:\windows\system32\drivers\ssudobex.sys
2012-09-13 21:22 . 2012-07-31 10:42 203104 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2012-09-13 21:22 . 2012-07-31 10:42 102240 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2012-09-13 21:09 . 2012-09-13 21:09 -------- d-----w- C:\Temp
2012-09-13 20:09 . 2012-06-27 08:37 708168 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2012-09-13 20:09 . 2012-06-27 08:37 1490656 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2012-09-13 20:06 . 2012-08-28 08:05 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2012-09-13 20:05 . 2012-09-13 20:05 -------- d-----w- c:\program files (x86)\MarkAny
2012-09-13 20:04 . 2012-09-14 07:20 -------- d-----w- c:\programdata\Samsung
2012-09-13 20:04 . 2012-09-14 07:11 -------- d-----w- c:\program files (x86)\Samsung
2012-09-13 20:03 . 2012-09-14 21:37 -------- d-----w- C:\Images
2012-09-13 20:03 . 2012-09-14 06:04 -------- d-----w- c:\program files\WinRAR
2012-09-13 20:02 . 2012-03-06 20:55 -------- d-----w- C:\Wrar
2012-09-13 19:45 . 2012-09-13 19:45 -------- d-----w- c:\program files\CPUID
2012-09-13 19:37 . 2012-09-13 19:37 -------- d-----w- c:\windows\SysWow64\Macromed
2012-09-13 19:37 . 2012-09-13 12:42 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-13 19:37 . 2012-09-13 12:42 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-13 19:37 . 2012-09-13 19:37 -------- d-----w- c:\windows\system32\Macromed
2012-09-13 19:28 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-09-13 19:28 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-09-13 19:28 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-09-13 19:28 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-09-13 19:27 . 2012-06-02 13:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-09-13 19:27 . 2012-06-02 13:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- c:\program files (x86)\Amazon
2012-09-13 19:11 . 2012-09-14 13:34 -------- d-----w- c:\users\Tom
2012-09-13 19:09 . 2012-09-13 19:09 -------- d-----w- C:\Recovery
2012-09-13 18:45 . 2012-09-13 18:50 -------- d-----w- C:\Drivers
2012-09-13 17:59 . 2012-09-13 17:59 -------- d-----w- c:\program files (x86)\FlashGet Network
2012-09-13 15:57 . 2012-08-30 22:43 64462936 ----a-w- c:\windows\system32\MRT.exe
2012-09-13 15:32 . 2012-09-13 15:32 -------- d-----w- C:\NVIDIA
2012-09-13 15:32 . 2012-09-13 20:02 -------- d-----w- c:\program files (x86)\SpeedFan
2012-09-13 14:57 . 2012-09-14 21:10 -------- d-----w- C:\Downloads
2012-09-13 14:56 . 2012-09-13 14:56 -------- d-----w- c:\program files (x86)\Common Files\BitSpirit
2012-09-13 14:55 . 2012-09-14 15:11 -------- d-----w- c:\program files (x86)\BitSpirit
2012-09-13 14:53 . 2012-09-13 14:53 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-13 14:53 . 2012-09-13 14:53 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-13 14:53 . 2012-09-13 14:53 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-13 14:53 . 2012-09-13 14:53 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-13 14:53 . 2012-09-13 14:53 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-13 14:53 . 2012-09-13 14:53 188904 ----a-w- c:\windows\system32\java.exe
2012-09-13 14:53 . 2012-09-13 14:53 -------- d-----w- c:\program files\Java
2012-09-13 13:16 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-09-13 13:16 . 2012-04-24 05:37 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-09-13 13:16 . 2012-04-24 05:37 1462272 ----a-w- c:\windows\system32\crypt32.dll
2012-09-13 13:16 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-09-13 13:16 . 2012-04-24 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-09-13 13:16 . 2012-04-24 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-09-13 13:16 . 2012-09-14 21:45 -------- d-----w- c:\programdata\CyberLink
2012-09-13 13:16 . 2012-09-13 13:16 -------- d-----w- c:\users\Public\CyberLink
2012-09-13 13:15 . 2012-09-13 13:15 -------- d-----w- c:\programdata\FileOpen
2012-09-13 12:57 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2012-09-13 12:50 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-09-13 12:50 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
2012-09-13 12:50 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
2012-09-13 12:50 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
2012-09-13 12:50 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
2012-09-13 12:49 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-09-13 12:49 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-09-13 12:49 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-09-13 12:49 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-09-13 12:49 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-08-22 16:09 . 2012-08-22 16:09 -------- d-----w- c:\windows\util
2012-08-22 16:09 . 2012-08-22 16:09 57952 ----a-w- c:\windows\system32\drivers\fbfmon.sys
2012-08-22 16:09 . 2012-08-22 16:09 44896 ----a-w- c:\windows\system32\FbDefrag.exe
2012-08-22 16:09 . 2012-08-22 16:09 15968 ----a-w- c:\windows\system32\NFbfmon.dll
2012-08-22 16:09 . 2012-08-22 16:09 13408 ----a-w- c:\windows\system32\drivers\BPntDrv.sys
2012-08-22 16:09 . 2009-07-14 01:52 23120 ----a-w- c:\windows\system32\drivers\BootVid.dll
2012-08-22 16:09 . 2011-12-24 01:51 120160 ----a-w- c:\windows\system32\NSDSvc.exe
2012-08-22 16:09 . 2011-11-18 18:44 6496 ----a-w- c:\windows\system32\NSDSvcEL.dll
2012-08-22 16:09 . 2011-12-24 00:45 24160 ----a-w- c:\windows\system32\drivers\nsd.sys
2012-08-22 16:09 . 2011-12-22 04:57 59488 ----a-w- c:\windows\system32\drivers\Nsdfltr.sys
2012-08-22 16:09 . 2012-08-22 16:09 -------- d-----w- c:\program files\DIFX
2012-08-22 16:09 . 2012-08-22 16:08 39008 ----a-w- c:\windows\system32\drivers\LhdX64.sys
2012-08-22 16:09 . 2012-08-22 16:08 19872 ----a-w- c:\windows\system32\LenovoSDKEmSubSystem.dll
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\programdata\Downloaded Installations
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\programdata\OneKey Recovery
2012-08-22 16:08 . 2012-09-14 22:15 -------- d-----w- c:\program files (x86)\SugarSync
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\programdata\Partner
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\program files\Google
2012-08-22 16:05 . 2012-08-22 16:05 -------- d-----w- c:\programdata\YouCam
2012-08-22 16:05 . 2012-08-22 16:05 279392 ----a-w- c:\windows\system32\LenovoSdk.OKTDLL.dll
2012-08-22 16:05 . 2012-03-08 08:01 133 ----a-w- c:\programdata\Microsoft\Windows\OFFICEICON.vbs
2012-08-22 16:05 . 2012-02-22 14:35 291 ----a-w- c:\programdata\Microsoft\Windows\OFFICEICON.CMD
2012-08-22 16:03 . 2012-08-22 16:03 -------- d-----w- c:\program files (x86)\Lenovo Registration
2012-08-22 16:03 . 2012-02-22 11:29 10248 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2012-08-22 16:02 . 2012-05-25 15:13 162224 ----a-w- c:\windows\system32\mfevtps.exe
2012-08-22 16:02 . 2012-08-22 16:02 -------- d-----w- c:\program files (x86)\mcafee.com
2012-08-22 16:02 . 2012-08-22 16:03 -------- d-----w- c:\program files\mcafee
2012-08-22 16:02 . 2012-08-22 16:03 -------- d-----w- c:\program files (x86)\McAfee
2012-08-22 16:02 . 2012-08-22 16:03 -------- d-----w- c:\program files (x86)\Common Files\mcafee
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-13 13:15 . 2010-06-24 18:33 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-08-22 16:08 . 2011-12-15 21:09 30816 ----a-w- c:\windows\system32\drivers\AcpiVpc.sys
2012-08-22 15:03 . 2012-08-22 15:03 340992 ----a-w- c:\windows\system32\schannel.dll
2012-08-22 15:03 . 2012-08-22 15:03 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-08-22 15:00 . 2012-08-22 15:00 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\qwavedrv.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 5632 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\ndiscap.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\scfilter.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 50176 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\tcpip.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 27136 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\bfe.dll.mui
2012-08-22 15:00 . 2012-08-22 15:00 15360 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\pacer.sys.mui
2012-06-21 11:23 . 2012-06-21 11:23 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2012-08-22 16:08 433648 ----a-w- c:\programdata\Partner\Partner.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-08-28 3671904]
"Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-21 1174016]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-08-22 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2011-12-05 291096]
"LockKey"="c:\program files (x86)\LockKey\LockKey.exe" [2011-08-26 337776]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-30 284440]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1675160]
"Lenovo Registration"="c:\program files (x86)\Lenovo Registration\LenovoReg.exe" [2012-01-26 4351712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Lenovo\Bluetooth Software\BtwProximityCP.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R1 BPntDrv;BPntDrv;c:\windows\system32\drivers\BPntDrv.sys [2012-08-22 13408]
R1 Nsdfltr;Nsdfltr;c:\windows\system32\drivers\Nsdfltr.sys [2011-12-22 59488]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-05 659968]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-12-05 135952]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 136176]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-30 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-03 628448]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-28 161560]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R2 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-21 69640]
R2 NSDSvc;Fast boot service of lenovo;c:\windows\System32\NSDSvc.exe [2011-12-24 120160]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-28 363800]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2011-12-08 594704]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-12-05 195584]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-12-05 195584]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-02-02 134696]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2012-02-02 615976]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2012-02-02 39976]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 cphs;Intel(R) Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-06-07 276288]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-07-31 102240]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 136176]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2012-01-27 34200]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2011-08-25 173656]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-01-28 225216]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-12-08 273168]
R3 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-23 2458944]
R3 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe [2012-08-22 332272]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-07-31 203104]
R3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudobex.sys [2012-07-31 203104]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 vm2uvcflt;Vimicro USB Camera Filter 2;c:\windows\system32\Drivers\vm2uvcflt.sys [2011-08-06 14288]
R3 vm332avs;Lenovo Camera2;c:\windows\system32\Drivers\vm332avs.sys [2011-09-28 249040]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]
R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-13 250568]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 fbfmon;fbfmon;c:\windows\system32\drivers\fbfmon.sys [2012-08-22 57952]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2011-12-05 16152]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [2012-08-22 39008]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]
S0 NSD;NSD;c:\windows\system32\drivers\nsd.sys [2011-12-24 24160]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-08-30 30056]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-14 283200]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2011-01-25 60416]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-05-25 210616]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-05-25 162224]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2012-08-22 30816]
S3 hswpan;WPAN Driver;c:\windows\system32\DRIVERS\hswpan.sys [2012-01-27 109056]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2011-12-05 355096]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2011-12-05 785688]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2012-01-27 25496]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2012-03-02 104048]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2011-11-09 60184]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-12-02 11417088]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2011-01-25 18432]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-13 12:42]
.
2012-09-14 c:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
- c:\program files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2012-09-14 12:12]
.
2012-09-14 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2012-09-14 12:12]
.
2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 16:07]
.
2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 16:07]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2012-08-22 16:08 750064 ----a-w- c:\programdata\Partner\Partner64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-06-07 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-06-07 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-06-07 440128]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-27 12343400]
"OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2012-08-22 789856]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2012-08-22 8079408]
"Lenovo EE Boot Optimizer"="c:\program files (x86)\Lenovo\Boot Optimizer\PopWnd.exe" [2012-08-22 206176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=KMOH&bmod=KMOH
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Stáhnout pomocí &BitSpiritu - c:\program files (x86)\BitSpirit\bsurl.htm
TCP: DhcpNameServer = 192.168.43.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} - (no file)
ShellIconOverlayIdentifiers-{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} - (no file)
ShellIconOverlayIdentifiers-{A759AFF6-5851-457D-A540-F4ECED148351} - (no file)
ShellIconOverlayIdentifiers-{1574C9EF-7D58-488F-B358-8B78C1538F51} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SynLenovoGestureMgr - c:\program files (x86)\Synaptics\SynTP\SynLenovoGestureMgr.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-09-15 14:17:46
ComboFix-quarantined-files.txt 2012-09-15 12:17
.
Před spuštěním: Volných bajtů: 835 892 559 872
Po spuštění: Volných bajtů: 838 105 763 840
.
- - End Of File - - A90792598F9EEAB820E6F50463994133
Tady je LOG:
ComboFix 12-09-14.03 - Tom 15.09.2012 14:12:34.2.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3998.2882 [GMT 2:00]
Spuštěný z: c:\users\Tom\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\users\Public\AlexaNSISPlugin.2688.dll
c:\users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum
c:\users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum\Live Security Platinum.lnk
c:\windows\SysWow64\muzapp.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 12:16 . 2012-09-15 12:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-15 12:00 . 2012-09-15 12:01 -------- d-----w- c:\program files\trend micro
2012-09-15 12:00 . 2012-09-15 12:01 -------- d-----w- C:\rsit
2012-09-15 11:24 . 2012-09-15 11:49 -------- d-----w- c:\programdata\7531CCCB00011628005484B8F875F002
2012-09-14 23:04 . 2012-09-14 23:04 -------- d-----w- c:\programdata\RELOADED
2012-09-14 22:58 . 2012-09-14 23:04 -------- d-----w- c:\program files (x86)\The Walking Dead Episode 3
2012-09-14 22:48 . 2012-09-14 22:48 -------- d-----w- c:\program files (x86)\Telltale Games
2012-09-14 22:09 . 2010-06-02 02:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2012-09-14 22:09 . 2010-06-02 02:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2012-09-14 21:53 . 2012-09-15 11:26 -------- d-----w- c:\program files (x86)\Rage
2012-09-14 21:52 . 2012-09-14 22:11 -------- d-sh--w- c:\windows\ei_temp
2012-09-14 21:41 . 2012-09-14 21:41 -------- d-----w- c:\program files (x86)\The Walking Dead
2012-09-14 20:57 . 2012-09-14 20:57 -------- d-----w- C:\Fraps
2012-09-14 20:48 . 2012-09-14 20:48 1998168 ----a-w- c:\windows\SysWow64\d3dx9_43.dll
2012-09-14 20:44 . 2006-03-31 10:40 352464 ----a-w- c:\windows\system32\xactengine2_1.dll
2012-09-14 20:43 . 2012-09-14 20:43 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2012-09-14 20:29 . 2010-11-11 10:46 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2012-09-14 20:29 . 2012-09-14 20:29 2106216 ----a-w- c:\windows\SysWow64\d3dcompiler_43.dll
2012-09-14 20:28 . 2012-09-14 20:37 -------- d-----w- c:\program files (x86)\Dll-Files.com Fixer
2012-09-14 20:28 . 2012-09-14 20:27 3799904 ----a-w- c:\windows\system32\dffsetup-d3dcompiler_43.exe
2012-09-14 19:31 . 2012-09-14 19:31 -------- d-----w- c:\program files (x86)\THQ
2012-09-14 18:28 . 2012-09-14 18:28 -------- d-----w- c:\program files (x86)\PANDORA.TV
2012-09-14 18:28 . 2012-09-14 23:21 -------- d-----w- c:\program files (x86)\The KMPlayer
2012-09-14 18:27 . 2012-09-14 18:27 -------- d-----w- c:\programdata\Ask
2012-09-14 17:54 . 2012-09-14 22:15 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-09-14 17:54 . 2012-09-14 17:55 -------- d-----w- c:\programdata\Blizzard Entertainment
2012-09-14 17:53 . 2012-09-14 17:54 -------- d-----w- c:\programdata\Battle.net
2012-09-14 17:40 . 2012-09-14 17:40 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-09-14 17:40 . 2012-09-14 17:40 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-09-14 17:38 . 2012-09-14 17:43 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-09-14 05:37 . 2012-09-14 06:36 -------- d-----w- C:\totalcmd
2012-09-13 23:19 . 2012-09-13 23:19 -------- d-----w- C:\AllShare
2012-09-13 22:23 . 2012-09-13 22:23 -------- d-----w- c:\program files (x86)\Common Files\Wondershare
2012-09-13 22:23 . 2012-09-13 22:23 -------- d-----w- c:\program files (x86)\Wondershare
2012-09-13 21:22 . 2012-07-31 10:42 203104 ----a-w- c:\windows\system32\drivers\ssudobex.sys
2012-09-13 21:22 . 2012-07-31 10:42 203104 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2012-09-13 21:22 . 2012-07-31 10:42 102240 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2012-09-13 21:09 . 2012-09-13 21:09 -------- d-----w- C:\Temp
2012-09-13 20:09 . 2012-06-27 08:37 708168 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2012-09-13 20:09 . 2012-06-27 08:37 1490656 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2012-09-13 20:06 . 2012-08-28 08:05 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2012-09-13 20:05 . 2012-09-13 20:05 -------- d-----w- c:\program files (x86)\MarkAny
2012-09-13 20:04 . 2012-09-14 07:20 -------- d-----w- c:\programdata\Samsung
2012-09-13 20:04 . 2012-09-14 07:11 -------- d-----w- c:\program files (x86)\Samsung
2012-09-13 20:03 . 2012-09-14 21:37 -------- d-----w- C:\Images
2012-09-13 20:03 . 2012-09-14 06:04 -------- d-----w- c:\program files\WinRAR
2012-09-13 20:02 . 2012-03-06 20:55 -------- d-----w- C:\Wrar
2012-09-13 19:45 . 2012-09-13 19:45 -------- d-----w- c:\program files\CPUID
2012-09-13 19:37 . 2012-09-13 19:37 -------- d-----w- c:\windows\SysWow64\Macromed
2012-09-13 19:37 . 2012-09-13 12:42 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-13 19:37 . 2012-09-13 12:42 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-13 19:37 . 2012-09-13 19:37 -------- d-----w- c:\windows\system32\Macromed
2012-09-13 19:28 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-09-13 19:28 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-09-13 19:28 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-09-13 19:28 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-09-13 19:27 . 2012-06-02 13:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-09-13 19:27 . 2012-06-02 13:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- c:\program files (x86)\Amazon
2012-09-13 19:11 . 2012-09-14 13:34 -------- d-----w- c:\users\Tom
2012-09-13 19:09 . 2012-09-13 19:09 -------- d-----w- C:\Recovery
2012-09-13 18:45 . 2012-09-13 18:50 -------- d-----w- C:\Drivers
2012-09-13 17:59 . 2012-09-13 17:59 -------- d-----w- c:\program files (x86)\FlashGet Network
2012-09-13 15:57 . 2012-08-30 22:43 64462936 ----a-w- c:\windows\system32\MRT.exe
2012-09-13 15:32 . 2012-09-13 15:32 -------- d-----w- C:\NVIDIA
2012-09-13 15:32 . 2012-09-13 20:02 -------- d-----w- c:\program files (x86)\SpeedFan
2012-09-13 14:57 . 2012-09-14 21:10 -------- d-----w- C:\Downloads
2012-09-13 14:56 . 2012-09-13 14:56 -------- d-----w- c:\program files (x86)\Common Files\BitSpirit
2012-09-13 14:55 . 2012-09-14 15:11 -------- d-----w- c:\program files (x86)\BitSpirit
2012-09-13 14:53 . 2012-09-13 14:53 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-13 14:53 . 2012-09-13 14:53 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-13 14:53 . 2012-09-13 14:53 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-13 14:53 . 2012-09-13 14:53 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-13 14:53 . 2012-09-13 14:53 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-13 14:53 . 2012-09-13 14:53 188904 ----a-w- c:\windows\system32\java.exe
2012-09-13 14:53 . 2012-09-13 14:53 -------- d-----w- c:\program files\Java
2012-09-13 13:16 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-09-13 13:16 . 2012-04-24 05:37 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-09-13 13:16 . 2012-04-24 05:37 1462272 ----a-w- c:\windows\system32\crypt32.dll
2012-09-13 13:16 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-09-13 13:16 . 2012-04-24 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-09-13 13:16 . 2012-04-24 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-09-13 13:16 . 2012-09-14 21:45 -------- d-----w- c:\programdata\CyberLink
2012-09-13 13:16 . 2012-09-13 13:16 -------- d-----w- c:\users\Public\CyberLink
2012-09-13 13:15 . 2012-09-13 13:15 -------- d-----w- c:\programdata\FileOpen
2012-09-13 12:57 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2012-09-13 12:50 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-09-13 12:50 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
2012-09-13 12:50 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
2012-09-13 12:50 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
2012-09-13 12:50 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
2012-09-13 12:49 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-09-13 12:49 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-09-13 12:49 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-09-13 12:49 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-09-13 12:49 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-08-22 16:09 . 2012-08-22 16:09 -------- d-----w- c:\windows\util
2012-08-22 16:09 . 2012-08-22 16:09 57952 ----a-w- c:\windows\system32\drivers\fbfmon.sys
2012-08-22 16:09 . 2012-08-22 16:09 44896 ----a-w- c:\windows\system32\FbDefrag.exe
2012-08-22 16:09 . 2012-08-22 16:09 15968 ----a-w- c:\windows\system32\NFbfmon.dll
2012-08-22 16:09 . 2012-08-22 16:09 13408 ----a-w- c:\windows\system32\drivers\BPntDrv.sys
2012-08-22 16:09 . 2009-07-14 01:52 23120 ----a-w- c:\windows\system32\drivers\BootVid.dll
2012-08-22 16:09 . 2011-12-24 01:51 120160 ----a-w- c:\windows\system32\NSDSvc.exe
2012-08-22 16:09 . 2011-11-18 18:44 6496 ----a-w- c:\windows\system32\NSDSvcEL.dll
2012-08-22 16:09 . 2011-12-24 00:45 24160 ----a-w- c:\windows\system32\drivers\nsd.sys
2012-08-22 16:09 . 2011-12-22 04:57 59488 ----a-w- c:\windows\system32\drivers\Nsdfltr.sys
2012-08-22 16:09 . 2012-08-22 16:09 -------- d-----w- c:\program files\DIFX
2012-08-22 16:09 . 2012-08-22 16:08 39008 ----a-w- c:\windows\system32\drivers\LhdX64.sys
2012-08-22 16:09 . 2012-08-22 16:08 19872 ----a-w- c:\windows\system32\LenovoSDKEmSubSystem.dll
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\programdata\Downloaded Installations
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\programdata\OneKey Recovery
2012-08-22 16:08 . 2012-09-14 22:15 -------- d-----w- c:\program files (x86)\SugarSync
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\programdata\Partner
2012-08-22 16:08 . 2012-08-22 16:08 -------- d-----w- c:\program files\Google
2012-08-22 16:05 . 2012-08-22 16:05 -------- d-----w- c:\programdata\YouCam
2012-08-22 16:05 . 2012-08-22 16:05 279392 ----a-w- c:\windows\system32\LenovoSdk.OKTDLL.dll
2012-08-22 16:05 . 2012-03-08 08:01 133 ----a-w- c:\programdata\Microsoft\Windows\OFFICEICON.vbs
2012-08-22 16:05 . 2012-02-22 14:35 291 ----a-w- c:\programdata\Microsoft\Windows\OFFICEICON.CMD
2012-08-22 16:03 . 2012-08-22 16:03 -------- d-----w- c:\program files (x86)\Lenovo Registration
2012-08-22 16:03 . 2012-02-22 11:29 10248 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2012-08-22 16:02 . 2012-05-25 15:13 162224 ----a-w- c:\windows\system32\mfevtps.exe
2012-08-22 16:02 . 2012-08-22 16:02 -------- d-----w- c:\program files (x86)\mcafee.com
2012-08-22 16:02 . 2012-08-22 16:03 -------- d-----w- c:\program files\mcafee
2012-08-22 16:02 . 2012-08-22 16:03 -------- d-----w- c:\program files (x86)\McAfee
2012-08-22 16:02 . 2012-08-22 16:03 -------- d-----w- c:\program files (x86)\Common Files\mcafee
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-13 13:15 . 2010-06-24 18:33 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-08-22 16:08 . 2011-12-15 21:09 30816 ----a-w- c:\windows\system32\drivers\AcpiVpc.sys
2012-08-22 15:03 . 2012-08-22 15:03 340992 ----a-w- c:\windows\system32\schannel.dll
2012-08-22 15:03 . 2012-08-22 15:03 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-08-22 15:00 . 2012-08-22 15:00 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\qwavedrv.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 5632 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\ndiscap.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\scfilter.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 50176 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\tcpip.sys.mui
2012-08-22 15:00 . 2012-08-22 15:00 27136 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\bfe.dll.mui
2012-08-22 15:00 . 2012-08-22 15:00 15360 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\pacer.sys.mui
2012-06-21 11:23 . 2012-06-21 11:23 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2012-08-22 16:08 433648 ----a-w- c:\programdata\Partner\Partner.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-08-28 3671904]
"Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-21 1174016]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-08-22 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2011-12-05 291096]
"LockKey"="c:\program files (x86)\LockKey\LockKey.exe" [2011-08-26 337776]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-30 284440]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1675160]
"Lenovo Registration"="c:\program files (x86)\Lenovo Registration\LenovoReg.exe" [2012-01-26 4351712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Lenovo\Bluetooth Software\BtwProximityCP.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R1 BPntDrv;BPntDrv;c:\windows\system32\drivers\BPntDrv.sys [2012-08-22 13408]
R1 Nsdfltr;Nsdfltr;c:\windows\system32\drivers\Nsdfltr.sys [2011-12-22 59488]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-05 659968]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-12-05 135952]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 136176]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-30 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-03 628448]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-28 161560]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R2 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-21 69640]
R2 NSDSvc;Fast boot service of lenovo;c:\windows\System32\NSDSvc.exe [2011-12-24 120160]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-28 363800]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2011-12-08 594704]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-12-05 195584]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-12-05 195584]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-02-02 134696]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2012-02-02 615976]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2012-02-02 39976]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 cphs;Intel(R) Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-06-07 276288]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-07-31 102240]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 136176]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2012-01-27 34200]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2011-08-25 173656]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-01-28 225216]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-12-08 273168]
R3 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-23 2458944]
R3 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe [2012-08-22 332272]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-07-31 203104]
R3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudobex.sys [2012-07-31 203104]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 vm2uvcflt;Vimicro USB Camera Filter 2;c:\windows\system32\Drivers\vm2uvcflt.sys [2011-08-06 14288]
R3 vm332avs;Lenovo Camera2;c:\windows\system32\Drivers\vm332avs.sys [2011-09-28 249040]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]
R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-13 250568]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 fbfmon;fbfmon;c:\windows\system32\drivers\fbfmon.sys [2012-08-22 57952]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2011-12-05 16152]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [2012-08-22 39008]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]
S0 NSD;NSD;c:\windows\system32\drivers\nsd.sys [2011-12-24 24160]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-08-30 30056]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-14 283200]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2011-01-25 60416]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-05-25 210616]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-05-25 162224]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2012-08-22 30816]
S3 hswpan;WPAN Driver;c:\windows\system32\DRIVERS\hswpan.sys [2012-01-27 109056]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2011-12-05 355096]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2011-12-05 785688]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2012-01-27 25496]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2012-03-02 104048]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2011-11-09 60184]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-12-02 11417088]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2011-01-25 18432]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-13 12:42]
.
2012-09-14 c:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
- c:\program files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2012-09-14 12:12]
.
2012-09-14 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2012-09-14 12:12]
.
2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 16:07]
.
2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22 16:07]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2012-08-22 16:08 750064 ----a-w- c:\programdata\Partner\Partner64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-06-07 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-06-07 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-06-07 440128]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-27 12343400]
"OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2012-08-22 789856]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2012-08-22 8079408]
"Lenovo EE Boot Optimizer"="c:\program files (x86)\Lenovo\Boot Optimizer\PopWnd.exe" [2012-08-22 206176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=KMOH&bmod=KMOH
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Stáhnout pomocí &BitSpiritu - c:\program files (x86)\BitSpirit\bsurl.htm
TCP: DhcpNameServer = 192.168.43.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} - (no file)
ShellIconOverlayIdentifiers-{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} - (no file)
ShellIconOverlayIdentifiers-{A759AFF6-5851-457D-A540-F4ECED148351} - (no file)
ShellIconOverlayIdentifiers-{1574C9EF-7D58-488F-B358-8B78C1538F51} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SynLenovoGestureMgr - c:\program files (x86)\Synaptics\SynTP\SynLenovoGestureMgr.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-09-15 14:17:46
ComboFix-quarantined-files.txt 2012-09-15 12:17
.
Před spuštěním: Volných bajtů: 835 892 559 872
Po spuštění: Volných bajtů: 838 105 763 840
.
- - End Of File - - A90792598F9EEAB820E6F50463994133
Re: Live security platinum - EDIT: prosím o kontrolu logu
Zdravim
Co se tyce ComboFixu, tak na zaklade licence a pravidel fora ptam, umite s nim pracovat (spusteni, rozlusteni logu, napsani skriptu)?
licencni podminky hovori jasne "Nikdy by nemel byt pouzit v prostredi bez dozoru zkusene osoby"

Nebezpeci CFka

- Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
- Maze stopy po haveti, takze v logu z RSIT neni nic videt
- Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
- CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
- CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
Re: Live security platinum - EDIT: prosím o kontrolu logu
Jak to tu vypada
Pokud nebude zde vyvijena nejaka cinnost - bude tema na zaklade Pravidla o zamykani temat
Pokud nebude zde vyvijena nejaka cinnost - bude tema na zaklade Pravidla o zamykani temat



Přispějete na provoz fóra?