Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se
jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine
aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,
pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k
nezadoucim kolizim s rezidentem antispyware

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Vyskakovanie okna
Moderátor: Moderátoři
- Rudy
- Site Admin
- Příspěvky: 119412
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vyskakovanie okna
Zkuste obnovu systému k datu, kdy korektně fungoval. Pokud to nepomůže, dejte log ComboFix:
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 20
- Registrován: 26 lis 2012 21:15
Re: Vyskakovanie okna
Ked som chcel spraviť obnovu systemu, najstarši možny datum obnovy bol včerajši...tak dávam log
ComboFix 12-11-29.02 - Jano . 11. 2012 15:16:44.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4094.2646 [GMT 1:00]
Running from: c:\users\Jano\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jano\.filestore\Documents\Windows\phatk.cl
c:\users\Jano\AppData\Local\libeay32.dll
c:\users\Jano\AppData\Local\libssl32.dll
c:\users\Jano\AppData\Roaming\CMDHost0.exe
c:\users\Jano\AppData\Roaming\HostServices6.exe
c:\users\Jano\AppData\Roaming\tep512133
c:\users\Jano\AppData\Roaming\tep512949
c:\users\Jano\AppData\Roaming\Win Update.exe
c:\users\Jano\drivers\explorer.exe
c:\users\Jano\msdata
c:\users\Jano\msdata\cmdhost_w1c.exe
c:\users\Jano\msdata\eCm_w1_new.exe
c:\users\Jano\msdata\ECM_W1_up.exe
c:\users\Jano\msdata\Ecm111.exe
c:\users\Jano\msdata\ecm2_w2.exe
c:\users\Jano\msdata\ecm4_w1.exe
c:\users\Jano\msdata\emc.exe
c:\users\Jano\msdata\explorer.exe
c:\users\Jano\msdata\iexplorer.exe
c:\users\Jano\msdata\ltc_w1.exe
c:\users\Jano\msdata\microsofteula.exe
c:\users\Jano\msdata\netdaemon.exe
C:\WGASetup.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Files Created from 2012-10-28 to 2012-11-29 )))))))))))))))))))))))))))))))
.
.
2012-11-29 14:21 . 2012-11-29 14:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-29 14:06 . 2012-11-29 14:06 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B87E0469-A11E-45F2-8D8F-972560045597}\offreg.dll
2012-11-27 16:30 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B87E0469-A11E-45F2-8D8F-972560045597}\mpengine.dll
2012-11-27 16:08 . 2012-11-28 08:19 -------- d-----w- c:\program files\trend micro
2012-11-24 17:11 . 2012-11-24 17:11 -------- d-----w- c:\users\Jano\AppData\Roaming\HEWGBhyj HJERe
2012-11-21 20:23 . 2012-11-21 20:23 -------- d-----w- c:\users\Jano\AppData\Roaming\Theta
2012-11-21 17:12 . 2012-11-21 17:12 -------- d-sh--w- c:\users\Jano\Userdata
2012-11-21 17:12 . 2012-11-29 14:20 -------- d-sh--w- c:\users\Jano\Drivers
2012-11-20 14:12 . 2012-11-20 14:12 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-11-19 18:31 . 2012-11-19 18:31 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2012-11-17 09:26 . 2012-11-17 09:38 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-11-16 17:08 . 2012-11-16 17:08 -------- d-----w- c:\program files (x86)\Activision
2012-11-16 13:56 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-16 13:56 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-16 13:56 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-16 13:56 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-16 13:51 . 2012-10-08 12:19 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-11-16 13:51 . 2012-10-08 11:42 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-11-16 13:51 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-16 13:51 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-16 13:51 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-16 13:51 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-16 13:51 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-16 13:51 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-16 13:51 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-16 13:01 . 2012-10-18 18:18 3147264 ----a-w- c:\windows\system32\win32k.sys
2012-11-16 13:00 . 2012-09-25 22:39 95744 ----a-w- c:\windows\system32\synceng.dll
2012-11-16 13:00 . 2012-09-25 21:55 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2012-11-15 22:31 . 2012-11-15 22:31 -------- d-----w- c:\programdata\ATI
2012-11-15 22:31 . 2012-11-15 22:31 -------- d-----w- c:\program files (x86)\AMD AVT
2012-11-15 22:31 . 2012-11-15 22:31 -------- d-----w- c:\program files (x86)\AMD APP
2012-11-12 20:52 . 2012-11-12 20:52 5624488 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-11-12 20:50 . 2012-11-12 20:50 11270656 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-11-12 20:36 . 2012-11-12 20:36 23436288 ----a-w- c:\windows\system32\atio6axx.dll
2012-11-12 20:29 . 2012-11-12 20:29 70144 ----a-w- c:\windows\system32\coinst_9.01.8.dll
2012-11-12 20:27 . 2012-11-12 20:27 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-11-12 20:25 . 2012-11-12 20:25 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-11-12 20:25 . 2012-11-12 20:25 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-11-12 20:25 . 2012-11-12 20:25 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-11-12 20:25 . 2012-11-12 20:25 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-11-12 20:25 . 2012-11-12 20:25 16082944 ----a-w- c:\windows\system32\aticaldd64.dll
2012-11-12 20:21 . 2012-11-12 20:21 13703168 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-11-12 20:19 . 2012-11-12 20:19 18958336 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-11-12 20:18 . 2012-11-12 20:18 949248 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-11-12 20:14 . 2012-11-12 20:14 6678528 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-11-12 20:04 . 2012-11-12 20:04 442368 ----a-w- c:\windows\system32\atidemgy.dll
2012-11-12 20:04 . 2012-11-12 20:04 548864 ----a-w- c:\windows\system32\atieclxx.exe
2012-11-12 20:03 . 2012-11-12 20:03 240640 ----a-w- c:\windows\system32\atiesrxx.exe
2012-11-12 20:02 . 2012-11-12 20:02 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-11-12 20:02 . 2012-11-12 20:02 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-11-12 20:02 . 2012-11-12 20:02 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-11-12 20:02 . 2012-11-12 20:02 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-11-12 20:00 . 2012-11-12 20:00 4674048 ----a-w- c:\windows\system32\atiumd6a.dll
2012-11-12 19:52 . 2012-11-12 19:52 6779392 ----a-w- c:\windows\system32\atiumd64.dll
2012-11-12 19:49 . 2012-11-12 19:49 3862528 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-11-12 19:41 . 2012-11-12 19:41 618496 ----a-w- c:\windows\system32\atiadlxx.dll
2012-11-12 19:41 . 2012-11-12 19:41 421888 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-11-12 19:41 . 2012-11-12 19:41 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-11-12 19:40 . 2012-11-12 19:40 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 546304 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-11-12 19:40 . 2012-11-12 19:40 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-11-12 19:40 . 2012-11-12 19:40 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-11-12 19:40 . 2012-11-12 19:40 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-11-12 19:40 . 2012-11-12 19:40 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-11-12 19:38 . 2012-11-12 19:38 130048 ----a-w- c:\windows\system32\atiuxp64.dll
2012-11-12 19:38 . 2012-11-12 19:38 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-11-12 19:38 . 2012-11-12 19:38 104448 ----a-w- c:\windows\system32\atiu9p64.dll
2012-11-12 19:38 . 2012-11-12 19:38 83968 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-11-12 19:37 . 2012-11-12 19:37 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-11-12 14:46 . 2012-11-12 14:46 222720 ----a-w- c:\windows\system32\clinfo.exe
2012-11-12 14:46 . 2012-11-12 14:46 76288 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-11-12 14:46 . 2012-11-12 14:46 65536 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-11-12 14:46 . 2012-11-12 14:46 64512 ----a-w- c:\windows\system32\OVDecode64.dll
2012-11-12 14:46 . 2012-11-12 14:46 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-11-12 14:46 . 2012-11-12 14:46 34523136 ----a-w- c:\windows\system32\amdocl64.dll
2012-11-12 14:41 . 2012-11-12 14:41 28737536 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-11-12 14:37 . 2012-11-12 14:37 54784 ----a-w- c:\windows\system32\OpenCL.dll
2012-11-12 14:37 . 2012-11-12 14:37 50176 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-11-06 14:48 . 2012-11-06 14:48 -------- d-----w- c:\users\Jano\AppData\Local\Programs
2012-10-31 15:48 . 2012-10-31 15:48 -------- d-----w- c:\program files (x86)\Gophoto.it
2012-10-31 15:47 . 2012-10-31 15:47 -------- d-----w- c:\program files (x86)\OnlineHD.TV
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-29 14:03 . 2010-09-05 09:00 25640 ----a-w- c:\windows\gdrv.sys
2012-11-21 14:31 . 2010-10-20 19:55 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-11-21 14:31 . 2010-10-20 19:55 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-16 12:55 . 2010-09-05 16:01 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-11-12 20:16 . 2010-08-04 01:54 1137664 ----a-w- c:\windows\system32\aticfx64.dll
2012-11-12 19:56 . 2009-11-04 15:31 7370752 ----a-w- c:\windows\system32\atidxx64.dll
2012-10-16 21:20 . 2012-11-28 12:52 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 21:20 . 2012-11-28 12:52 347648 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 20:34 . 2012-11-28 12:52 559104 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-09 15:49 . 2012-05-08 07:13 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-09 15:49 . 2012-01-04 11:20 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-14 19:23 . 2012-10-10 11:01 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-14 18:30 . 2012-10-10 11:01 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-09-06 16:05 . 2012-09-06 16:05 3953152 ----a-w- c:\windows\system32\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 2839552 ----a-w- c:\windows\SysWow64\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 198144 ----a-w- c:\windows\system32\SlotMaximizerAg.dll
2012-09-06 16:05 . 2012-09-06 16:05 161792 ----a-w- c:\windows\SysWow64\SlotMaximizerAg.dll
2012-08-31 18:02 . 2012-10-10 11:02 1656688 ----a-w- c:\windows\system32\drivers\ntfs.sys
2008-03-09 05:25 . 2010-09-13 17:45 236 ----a-w- c:\program files (x86)\Common Files\dx.reg
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-06-20 2736128]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Sony PC Companion"="c:\program files (x86)\Sony\Sony PC Companion\PCCompanion.exe" [2012-09-12 445624]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2009-11-04 380928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-01-12 669520]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-12 642216]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-11-19 2254768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 Angelnt;Angelnt;c:\windows\System32\Drivers\ANGELNT.SYS [x]
R2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-05 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-05 834544]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2012-03-14 209768]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2012-03-14 148528]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-12 240640]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-11-12 361984]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2012-03-07 913144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2012-03-14 137144]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-19 2462128]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2012-10-23 103472]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-07-30 236544]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 14:05 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-08 15:49]
.
2012-11-27 c:\windows\Tasks\Epson Printer Software Downloader.job
- c:\program files (x86)\EPSON\EPAPDL\E_SAPDL2.EXE [2009-01-23 14:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-18 8067616]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 4081008]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-IRC - c:\users\Jano\.filestore\Documents\Windows\ircserver.exe
Wow6432Node-HKCU-Run-DLLService - c:\users\Jano\.filestore\Documents\Windows\igfxservice.exe
Wow6432Node-HKCU-Run-CommandUtilities - c:\users\Jano\.filestore\Documents\Windows\svuhost.exe
Wow6432Node-HKCU-Run-WindowsWorker - c:\users\Jano\.filestore\Documents\Windows\winworker.exe
Wow6432Node-HKCU-Run-CMDHost - c:\users\Jano\AppData\Roaming\CMDHost0.exe
Wow6432Node-HKCU-Run-HostServices - c:\users\Jano\AppData\Roaming\HostServices6.exe
Wow6432Node-HKLM-Run-Windows Explorer - c:\users\Jano\msdata\iexplorer.exe
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-DAEMON Tools Toolbar - c:\program files (x86)\DAEMON Tools Toolbar\uninst.exe
AddRemove-GamePlayLabs Plugin - c:\users\Jano\AppData\Local\GamePlayLabs Plugin\Uninstall.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2858087475-1341382447-2249875837-1001\Software\SecuROM\License information*]
"datasecu"=hex:d6,4a,cf,ca,6c,eb,8f,3c,5b,82,cc,a8,5d,77,ea,a6,5b,5f,1e,34,51,
13,39,03,19,58,18,12,6a,61,cb,e3,74,64,05,87,6c,c4,d9,ef,64,52,43,9c,7d,4d,\
"rkeysecu"=hex:3c,fa,22,74,4d,c3,10,13,79,66,f1,48,8f,43,3e,fa
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-29 15:22:16
ComboFix-quarantined-files.txt 2012-11-29 14:22
.
Pre-Run: 17 683 214 336 bytes free
Post-Run: 17 336 094 720 bytes free
.
- - End Of File - - 45B6A2372421934E757E09A8FE1C9075
ComboFix 12-11-29.02 - Jano . 11. 2012 15:16:44.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4094.2646 [GMT 1:00]
Running from: c:\users\Jano\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jano\.filestore\Documents\Windows\phatk.cl
c:\users\Jano\AppData\Local\libeay32.dll
c:\users\Jano\AppData\Local\libssl32.dll
c:\users\Jano\AppData\Roaming\CMDHost0.exe
c:\users\Jano\AppData\Roaming\HostServices6.exe
c:\users\Jano\AppData\Roaming\tep512133
c:\users\Jano\AppData\Roaming\tep512949
c:\users\Jano\AppData\Roaming\Win Update.exe
c:\users\Jano\drivers\explorer.exe
c:\users\Jano\msdata
c:\users\Jano\msdata\cmdhost_w1c.exe
c:\users\Jano\msdata\eCm_w1_new.exe
c:\users\Jano\msdata\ECM_W1_up.exe
c:\users\Jano\msdata\Ecm111.exe
c:\users\Jano\msdata\ecm2_w2.exe
c:\users\Jano\msdata\ecm4_w1.exe
c:\users\Jano\msdata\emc.exe
c:\users\Jano\msdata\explorer.exe
c:\users\Jano\msdata\iexplorer.exe
c:\users\Jano\msdata\ltc_w1.exe
c:\users\Jano\msdata\microsofteula.exe
c:\users\Jano\msdata\netdaemon.exe
C:\WGASetup.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Files Created from 2012-10-28 to 2012-11-29 )))))))))))))))))))))))))))))))
.
.
2012-11-29 14:21 . 2012-11-29 14:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-29 14:06 . 2012-11-29 14:06 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B87E0469-A11E-45F2-8D8F-972560045597}\offreg.dll
2012-11-27 16:30 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B87E0469-A11E-45F2-8D8F-972560045597}\mpengine.dll
2012-11-27 16:08 . 2012-11-28 08:19 -------- d-----w- c:\program files\trend micro
2012-11-24 17:11 . 2012-11-24 17:11 -------- d-----w- c:\users\Jano\AppData\Roaming\HEWGBhyj HJERe
2012-11-21 20:23 . 2012-11-21 20:23 -------- d-----w- c:\users\Jano\AppData\Roaming\Theta
2012-11-21 17:12 . 2012-11-21 17:12 -------- d-sh--w- c:\users\Jano\Userdata
2012-11-21 17:12 . 2012-11-29 14:20 -------- d-sh--w- c:\users\Jano\Drivers
2012-11-20 14:12 . 2012-11-20 14:12 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-11-19 18:31 . 2012-11-19 18:31 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2012-11-17 09:26 . 2012-11-17 09:38 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-11-16 17:08 . 2012-11-16 17:08 -------- d-----w- c:\program files (x86)\Activision
2012-11-16 13:56 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-16 13:56 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-16 13:56 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-16 13:56 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-16 13:51 . 2012-10-08 12:19 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-11-16 13:51 . 2012-10-08 11:42 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-11-16 13:51 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-16 13:51 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-16 13:51 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-16 13:51 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-16 13:51 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-16 13:51 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-16 13:51 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-16 13:01 . 2012-10-18 18:18 3147264 ----a-w- c:\windows\system32\win32k.sys
2012-11-16 13:00 . 2012-09-25 22:39 95744 ----a-w- c:\windows\system32\synceng.dll
2012-11-16 13:00 . 2012-09-25 21:55 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2012-11-15 22:31 . 2012-11-15 22:31 -------- d-----w- c:\programdata\ATI
2012-11-15 22:31 . 2012-11-15 22:31 -------- d-----w- c:\program files (x86)\AMD AVT
2012-11-15 22:31 . 2012-11-15 22:31 -------- d-----w- c:\program files (x86)\AMD APP
2012-11-12 20:52 . 2012-11-12 20:52 5624488 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-11-12 20:50 . 2012-11-12 20:50 11270656 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-11-12 20:36 . 2012-11-12 20:36 23436288 ----a-w- c:\windows\system32\atio6axx.dll
2012-11-12 20:29 . 2012-11-12 20:29 70144 ----a-w- c:\windows\system32\coinst_9.01.8.dll
2012-11-12 20:27 . 2012-11-12 20:27 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-11-12 20:25 . 2012-11-12 20:25 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-11-12 20:25 . 2012-11-12 20:25 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-11-12 20:25 . 2012-11-12 20:25 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-11-12 20:25 . 2012-11-12 20:25 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-11-12 20:25 . 2012-11-12 20:25 16082944 ----a-w- c:\windows\system32\aticaldd64.dll
2012-11-12 20:21 . 2012-11-12 20:21 13703168 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-11-12 20:19 . 2012-11-12 20:19 18958336 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-11-12 20:18 . 2012-11-12 20:18 949248 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-11-12 20:14 . 2012-11-12 20:14 6678528 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-11-12 20:04 . 2012-11-12 20:04 442368 ----a-w- c:\windows\system32\atidemgy.dll
2012-11-12 20:04 . 2012-11-12 20:04 548864 ----a-w- c:\windows\system32\atieclxx.exe
2012-11-12 20:03 . 2012-11-12 20:03 240640 ----a-w- c:\windows\system32\atiesrxx.exe
2012-11-12 20:02 . 2012-11-12 20:02 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-11-12 20:02 . 2012-11-12 20:02 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-11-12 20:02 . 2012-11-12 20:02 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-11-12 20:02 . 2012-11-12 20:02 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-11-12 20:00 . 2012-11-12 20:00 4674048 ----a-w- c:\windows\system32\atiumd6a.dll
2012-11-12 19:52 . 2012-11-12 19:52 6779392 ----a-w- c:\windows\system32\atiumd64.dll
2012-11-12 19:49 . 2012-11-12 19:49 3862528 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-11-12 19:41 . 2012-11-12 19:41 618496 ----a-w- c:\windows\system32\atiadlxx.dll
2012-11-12 19:41 . 2012-11-12 19:41 421888 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-11-12 19:41 . 2012-11-12 19:41 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-11-12 19:40 . 2012-11-12 19:40 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-11-12 19:40 . 2012-11-12 19:40 546304 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-11-12 19:40 . 2012-11-12 19:40 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-11-12 19:40 . 2012-11-12 19:40 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-11-12 19:40 . 2012-11-12 19:40 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-11-12 19:40 . 2012-11-12 19:40 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-11-12 19:38 . 2012-11-12 19:38 130048 ----a-w- c:\windows\system32\atiuxp64.dll
2012-11-12 19:38 . 2012-11-12 19:38 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-11-12 19:38 . 2012-11-12 19:38 104448 ----a-w- c:\windows\system32\atiu9p64.dll
2012-11-12 19:38 . 2012-11-12 19:38 83968 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-11-12 19:37 . 2012-11-12 19:37 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-11-12 14:46 . 2012-11-12 14:46 222720 ----a-w- c:\windows\system32\clinfo.exe
2012-11-12 14:46 . 2012-11-12 14:46 76288 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-11-12 14:46 . 2012-11-12 14:46 65536 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-11-12 14:46 . 2012-11-12 14:46 64512 ----a-w- c:\windows\system32\OVDecode64.dll
2012-11-12 14:46 . 2012-11-12 14:46 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-11-12 14:46 . 2012-11-12 14:46 34523136 ----a-w- c:\windows\system32\amdocl64.dll
2012-11-12 14:41 . 2012-11-12 14:41 28737536 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-11-12 14:37 . 2012-11-12 14:37 54784 ----a-w- c:\windows\system32\OpenCL.dll
2012-11-12 14:37 . 2012-11-12 14:37 50176 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-11-06 14:48 . 2012-11-06 14:48 -------- d-----w- c:\users\Jano\AppData\Local\Programs
2012-10-31 15:48 . 2012-10-31 15:48 -------- d-----w- c:\program files (x86)\Gophoto.it
2012-10-31 15:47 . 2012-10-31 15:47 -------- d-----w- c:\program files (x86)\OnlineHD.TV
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-29 14:03 . 2010-09-05 09:00 25640 ----a-w- c:\windows\gdrv.sys
2012-11-21 14:31 . 2010-10-20 19:55 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-11-21 14:31 . 2010-10-20 19:55 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-16 12:55 . 2010-09-05 16:01 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-11-12 20:16 . 2010-08-04 01:54 1137664 ----a-w- c:\windows\system32\aticfx64.dll
2012-11-12 19:56 . 2009-11-04 15:31 7370752 ----a-w- c:\windows\system32\atidxx64.dll
2012-10-16 21:20 . 2012-11-28 12:52 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 21:20 . 2012-11-28 12:52 347648 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 20:34 . 2012-11-28 12:52 559104 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-09 15:49 . 2012-05-08 07:13 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-09 15:49 . 2012-01-04 11:20 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-14 19:23 . 2012-10-10 11:01 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-14 18:30 . 2012-10-10 11:01 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-09-06 16:05 . 2012-09-06 16:05 3953152 ----a-w- c:\windows\system32\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 2839552 ----a-w- c:\windows\SysWow64\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 198144 ----a-w- c:\windows\system32\SlotMaximizerAg.dll
2012-09-06 16:05 . 2012-09-06 16:05 161792 ----a-w- c:\windows\SysWow64\SlotMaximizerAg.dll
2012-08-31 18:02 . 2012-10-10 11:02 1656688 ----a-w- c:\windows\system32\drivers\ntfs.sys
2008-03-09 05:25 . 2010-09-13 17:45 236 ----a-w- c:\program files (x86)\Common Files\dx.reg
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-06-20 2736128]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Sony PC Companion"="c:\program files (x86)\Sony\Sony PC Companion\PCCompanion.exe" [2012-09-12 445624]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2009-11-04 380928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-01-12 669520]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-12 642216]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-11-19 2254768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 Angelnt;Angelnt;c:\windows\System32\Drivers\ANGELNT.SYS [x]
R2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-05 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-05 834544]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2012-03-14 209768]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2012-03-14 148528]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-12 240640]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-11-12 361984]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2012-03-07 913144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2012-03-14 137144]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-19 2462128]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2012-10-23 103472]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-07-30 236544]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 14:05 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-08 15:49]
.
2012-11-27 c:\windows\Tasks\Epson Printer Software Downloader.job
- c:\program files (x86)\EPSON\EPAPDL\E_SAPDL2.EXE [2009-01-23 14:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-18 8067616]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 4081008]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-IRC - c:\users\Jano\.filestore\Documents\Windows\ircserver.exe
Wow6432Node-HKCU-Run-DLLService - c:\users\Jano\.filestore\Documents\Windows\igfxservice.exe
Wow6432Node-HKCU-Run-CommandUtilities - c:\users\Jano\.filestore\Documents\Windows\svuhost.exe
Wow6432Node-HKCU-Run-WindowsWorker - c:\users\Jano\.filestore\Documents\Windows\winworker.exe
Wow6432Node-HKCU-Run-CMDHost - c:\users\Jano\AppData\Roaming\CMDHost0.exe
Wow6432Node-HKCU-Run-HostServices - c:\users\Jano\AppData\Roaming\HostServices6.exe
Wow6432Node-HKLM-Run-Windows Explorer - c:\users\Jano\msdata\iexplorer.exe
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-DAEMON Tools Toolbar - c:\program files (x86)\DAEMON Tools Toolbar\uninst.exe
AddRemove-GamePlayLabs Plugin - c:\users\Jano\AppData\Local\GamePlayLabs Plugin\Uninstall.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2858087475-1341382447-2249875837-1001\Software\SecuROM\License information*]
"datasecu"=hex:d6,4a,cf,ca,6c,eb,8f,3c,5b,82,cc,a8,5d,77,ea,a6,5b,5f,1e,34,51,
13,39,03,19,58,18,12,6a,61,cb,e3,74,64,05,87,6c,c4,d9,ef,64,52,43,9c,7d,4d,\
"rkeysecu"=hex:3c,fa,22,74,4d,c3,10,13,79,66,f1,48,8f,43,3e,fa
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-29 15:22:16
ComboFix-quarantined-files.txt 2012-11-29 14:22
.
Pre-Run: 17 683 214 336 bytes free
Post-Run: 17 336 094 720 bytes free
.
- - End Of File - - 45B6A2372421934E757E09A8FE1C9075
- Rudy
- Site Admin
- Příspěvky: 119412
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vyskakovanie okna
OK. Řadu položek CF smazal, zbytek logu vypadá čistý. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 20
- Registrován: 26 lis 2012 21:15
Re: Vyskakovanie okna
Teraz som pustil PC zatial ide normálne
len to sa stávalo občas aj predtym že išiel normalne pri 1 z 5 spustení, keby sa ten problém náhodou vrátil tak napíšem....zatial velmi pekne ďakujem za pomoc 


- Rudy
- Site Admin
- Příspěvky: 119412
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vyskakovanie okna
OK. Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.