Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosím o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
michal1995
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 13 lis 2013 22:17

prosím o kontrolu

#1 Příspěvek od michal1995 »

ComboFix 13-11-12.01 - Michal 13.11.2013 21:54:27.1.8 - x64
Microsoft Windows 8 6.2.9200.0.1250.421.1051.18.8048.4631 [GMT 1:00]
Running from: c:\users\Michal\Downloads\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\saFe Saave
c:\programdata\saFe Saave\51e62877e6d86.tlb
c:\programdata\saFe Saave\data\safe saave.dat
c:\programdata\saFe Saave\settings.ini
c:\programdata\saFe Saave\uninstall.exe
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadlepppgmejbnjgiilhibclefcncbja
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadlepppgmejbnjgiilhibclefcncbja\1\51e62877e6b644.92282083.js
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadlepppgmejbnjgiilhibclefcncbja\1\background.html
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadlepppgmejbnjgiilhibclefcncbja\1\content.js
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadlepppgmejbnjgiilhibclefcncbja\1\lsdb.js
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadlepppgmejbnjgiilhibclefcncbja\1\manifest.json
c:\users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadlepppgmejbnjgiilhibclefcncbja\1\sqlite.js
c:\windows\SysWow64\FlashPlayerApp.exe
c:\windows\SysWow64\SET235C.tmp
c:\windows\SysWow64\SET3EC9.tmp
c:\windows\SysWow64\SET3F48.tmp
c:\windows\SysWow64\SET4AA7.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-10-13 to 2013-11-13 )))))))))))))))))))))))))))))))
.
.
2013-11-13 21:00 . 2013-11-13 21:00 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-11-13 21:00 . 2013-11-13 21:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-06 12:54 . 2013-11-06 12:54 342704 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10224.bin
2013-11-05 17:32 . 2013-11-05 17:32 -------- d-----w- c:\programdata\Package Cache
2013-10-31 08:22 . 2013-10-31 08:22 -------- d-----w- c:\windows\SysWow64\NV
2013-10-31 08:22 . 2013-10-31 08:22 -------- d-----w- c:\windows\system32\NV
2013-10-31 08:17 . 2013-10-23 10:30 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-10-31 08:17 . 2013-10-23 10:30 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-10-31 08:17 . 2013-10-23 10:30 9480328 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-10-31 08:17 . 2013-10-23 10:30 655136 ----a-w- c:\windows\system32\NvIFR64.dll
2013-10-31 08:17 . 2013-10-23 10:30 560416 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-10-31 08:17 . 2013-10-23 10:30 32544 ----a-w- c:\windows\system32\drivers\nvpciflt.sys
2013-10-31 08:17 . 2013-10-23 10:30 317472 ----a-w- c:\windows\system32\nvoglshim64.dll
2013-10-31 08:17 . 2013-10-23 10:30 30344480 ----a-w- c:\windows\system32\nvoglv64.dll
2013-10-31 08:17 . 2013-10-23 10:30 266984 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2013-10-31 08:17 . 2013-10-23 10:30 22933792 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-10-31 08:17 . 2013-10-23 10:30 12572960 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-10-31 08:17 . 2013-10-23 10:30 11374520 ----a-w- c:\windows\system32\nvopencl.dll
2013-10-28 19:59 . 2013-10-28 19:59 -------- d-----w- c:\users\Michal\AppData\Local\Aspyr
2013-10-28 19:57 . 2013-10-28 19:57 -------- d-----w- c:\program files (x86)\Sigma Production Inc
2013-10-28 19:55 . 2013-10-18 01:36 1063200 ----a-w- c:\windows\system32\nvspcap64.dll
2013-10-28 19:55 . 2013-10-18 01:36 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-10-28 19:54 . 2013-09-27 23:01 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-10-28 19:54 . 2013-09-27 23:01 28960 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-10-28 19:31 . 2013-10-28 19:31 -------- d-----w- c:\program files (x86)\Aspyr
2013-10-26 19:38 . 2013-10-26 19:38 -------- d-----w- c:\program files (x86)\Common Files\myCuteBuddy
2013-10-26 19:37 . 2013-10-26 19:38 -------- d-----w- c:\program files (x86)\My Cute Buddy
2013-10-26 19:36 . 2013-10-31 08:06 -------- d-----w- c:\program files (x86)\Iminent
2013-10-25 17:37 . 2013-10-25 17:37 -------- d-----w- c:\users\Michal\AppData\Roaming\Adobe Mini Bridge CS5
2013-10-25 17:37 . 2013-10-25 17:37 -------- d-----w- c:\users\Michal\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-10-24 14:15 . 2013-10-24 14:15 -------- d-----w- c:\users\Michal\AppData\Roaming\Unity
2013-10-23 02:02 . 2013-10-23 02:02 589600 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-10-21 18:11 . 2013-10-16 00:48 1884448 ----a-w- c:\windows\system32\nvdispco6433158.dll
2013-10-21 18:11 . 2013-10-16 00:48 1511712 ----a-w- c:\windows\system32\nvdispgenco6433158.dll
2013-10-17 18:23 . 2013-10-17 18:23 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-17 18:23 . 2013-10-17 18:23 -------- d-----w- c:\program files (x86)\Java
2013-10-17 18:18 . 2013-10-17 18:18 312744 ----a-w- c:\windows\system32\javaws.exe
2013-10-17 18:18 . 2013-10-17 18:18 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-10-17 18:18 . 2013-10-17 18:18 189352 ----a-w- c:\windows\system32\javaw.exe
2013-10-17 18:18 . 2013-10-17 18:18 189352 ----a-w- c:\windows\system32\java.exe
2013-10-17 18:18 . 2013-10-17 18:18 -------- d-----w- c:\program files\Java
2013-10-16 11:34 . 2013-10-16 11:34 -------- d-----w- c:\users\Michal\AppData\Roaming\Opera Software
2013-10-16 11:34 . 2013-10-16 11:34 -------- d-----w- c:\users\Michal\AppData\Local\Opera Software
2013-10-16 11:30 . 2013-08-03 06:40 566784 ----a-w- c:\windows\system32\wvc.dll
2013-10-16 11:30 . 2013-08-03 06:40 1374208 ----a-w- c:\windows\system32\wdc.dll
2013-10-16 11:30 . 2013-08-03 06:40 462336 ----a-w- c:\windows\system32\sysmon.ocx
2013-10-16 11:30 . 2013-08-03 05:13 1245696 ----a-w- c:\windows\SysWow64\wdc.dll
2013-10-16 11:30 . 2013-08-03 05:14 399360 ----a-w- c:\windows\SysWow64\sysmon.ocx
2013-10-16 11:30 . 2013-08-03 05:13 437248 ----a-w- c:\windows\SysWow64\wvc.dll
2013-10-16 11:30 . 2013-08-02 06:28 19758080 ----a-w- c:\windows\system32\shell32.dll
2013-10-16 11:30 . 2013-08-02 06:28 10116608 ----a-w- c:\windows\system32\twinui.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-10 18:23 . 2013-02-21 11:34 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-11-10 18:23 . 2013-02-21 11:34 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-11-10 18:23 . 2012-12-28 19:12 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-10-23 10:30 . 2012-11-03 23:34 3067560 ----a-w- c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2012-11-03 23:34 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2012-11-03 23:34 18199872 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-10-23 10:30 . 2012-11-03 23:34 168616 ----a-w- c:\windows\system32\nvinitx.dll
2013-10-23 10:30 . 2012-11-03 23:34 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-10-23 10:30 . 2012-11-03 23:34 1435504 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-10-23 10:30 . 2012-11-03 23:34 141336 ----a-w- c:\windows\SysWow64\nvinit.dll
2013-10-23 10:30 . 2012-11-03 23:34 1241376 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2013-10-23 08:20 . 2012-11-03 23:34 6669600 ----a-w- c:\windows\system32\nvcpl.dll
2013-10-23 08:20 . 2012-11-03 23:34 3489568 ----a-w- c:\windows\system32\nvsvc64.dll
2013-10-23 08:20 . 2012-11-03 23:34 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-10-23 08:20 . 2012-11-03 23:34 67072 ----a-w- c:\windows\system32\nv3dappshextr.dll
2013-10-23 08:20 . 2012-11-03 23:34 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-10-23 08:20 . 2012-11-03 23:34 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-10-23 08:20 . 2012-11-03 23:34 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-10-23 08:20 . 2012-11-03 23:34 1064224 ----a-w- c:\windows\system32\nv3dappshext.dll
2013-10-23 08:20 . 2012-11-03 23:34 597280 ----a-w- c:\windows\SysWow64\oemdspif.dll
2013-10-23 08:20 . 2012-11-03 23:34 3426956 ----a-w- c:\windows\system32\nvcoproc.bin
2013-10-08 21:44 . 2012-12-24 22:09 80541720 ----a-w- c:\windows\system32\MRT.exe
2013-10-02 01:38 . 2013-09-12 17:51 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-27 23:01 . 2013-08-02 06:01 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-09-25 05:25 . 2013-03-18 16:52 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-09-22 23:28 . 2013-10-08 21:12 1767936 ----a-w- c:\windows\SysWow64\wininet.dll
2013-09-22 23:27 . 2013-10-08 21:11 2876928 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-09-22 22:55 . 2013-10-08 21:12 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2013-09-22 22:55 . 2013-10-08 21:12 2241024 ----a-w- c:\windows\system32\wininet.dll
2013-09-22 22:55 . 2013-10-08 21:12 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-09-22 22:54 . 2013-10-08 21:12 603136 ----a-w- c:\windows\system32\msfeeds.dll
2013-09-22 22:54 . 2013-10-08 21:12 19252224 ----a-w- c:\windows\system32\mshtml.dll
2013-09-22 22:54 . 2013-10-08 21:12 855552 ----a-w- c:\windows\system32\jscript.dll
2013-09-22 22:54 . 2013-10-08 21:11 3959296 ----a-w- c:\windows\system32\jscript9.dll
2013-09-22 22:54 . 2013-10-08 21:12 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-09-22 22:54 . 2013-10-08 21:11 2647552 ----a-w- c:\windows\system32\iertutil.dll
2013-09-12 08:58 . 2013-09-23 17:31 1884448 ----a-w- c:\windows\system32\nvdispco6432723.dll
2013-09-12 08:58 . 2013-09-23 17:31 1511712 ----a-w- c:\windows\system32\nvdispgenco6432723.dll
2013-09-12 08:58 . 2012-11-03 23:34 2986672 ----a-w- c:\windows\system32\SETECF5.tmp
2013-09-12 08:58 . 2012-11-03 23:34 168616 ----a-w- c:\windows\system32\SETFAF8.tmp
2013-09-12 08:58 . 2012-11-03 23:34 15703688 ----a-w- c:\windows\system32\SETFAA7.tmp
2013-09-12 08:58 . 2012-11-03 23:34 1412832 ----a-w- c:\windows\system32\SETCD0.tmp
2013-08-30 07:48 . 2013-03-06 20:30 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2013-03-06 20:30 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2013-03-06 20:30 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2012-12-28 14:27 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2012-12-28 14:27 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2012-12-28 14:27 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2012-12-28 14:27 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2012-12-28 14:27 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2012-12-28 14:27 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2012-12-28 14:27 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-23 05:11 . 2013-10-08 21:10 4040192 ----a-w- c:\windows\system32\win32k.sys
2013-08-20 13:32 . 2013-08-02 06:01 29984 ----a-w- c:\windows\system32\SET85C6.tmp
2013-08-16 05:41 . 2013-09-10 19:39 58200 ----a-w- c:\windows\system32\drivers\dam.sys
2013-08-16 05:39 . 2013-09-10 19:39 2371728 ----a-w- c:\windows\system32\WSService.dll
2013-08-16 05:39 . 2013-09-10 19:39 59416 ----a-w- c:\windows\system32\wuauclt.exe
2013-08-16 05:32 . 2013-09-10 19:39 209200 ----a-w- c:\windows\system32\NotificationUI.exe
2013-08-16 05:22 . 2013-09-10 19:39 40448 ----a-w- c:\windows\system32\wuapp.exe
2013-08-16 05:22 . 2013-09-10 19:40 4917760 ----a-w- c:\windows\system32\sppsvc.exe
2013-08-16 05:21 . 2013-09-10 19:39 3275776 ----a-w- c:\windows\system32\wuaueng.dll
2013-08-16 05:21 . 2013-09-10 19:39 1621504 ----a-w- c:\windows\system32\wucltux.dll
2013-08-16 05:21 . 2013-09-10 19:39 99328 ----a-w- c:\windows\system32\wudriver.dll
2013-08-16 05:21 . 2013-09-10 19:39 49664 ----a-w- c:\windows\system32\wups.dll
2013-08-16 05:21 . 2013-09-10 19:39 49152 ----a-w- c:\windows\system32\wups2.dll
2013-08-16 05:21 . 2013-09-10 19:39 252416 ----a-w- c:\windows\system32\WUSettingsProvider.dll
2013-08-16 05:21 . 2013-09-10 19:39 142848 ----a-w- c:\windows\system32\wuwebv.dll
2013-08-16 05:21 . 2013-09-10 19:39 773120 ----a-w- c:\windows\system32\wuapi.dll
2013-08-16 05:21 . 2013-09-10 19:39 688640 ----a-w- c:\windows\system32\WSShared.dll
2013-08-16 05:21 . 2013-09-10 19:39 183808 ----a-w- c:\windows\system32\WSSync.dll
2013-08-16 05:21 . 2013-09-10 19:39 204800 ----a-w- c:\windows\system32\WSClient.dll
2013-08-16 05:21 . 2013-09-10 19:39 198656 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.dll
2013-08-16 05:21 . 2013-09-10 19:39 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-08-16 05:21 . 2013-09-10 19:39 174592 ----a-w- c:\windows\system32\storewuauth.dll
2013-08-16 05:21 . 2013-09-10 19:39 1164288 ----a-w- c:\windows\system32\sppobjs.dll
2013-08-16 05:21 . 2013-09-10 19:39 368640 ----a-w- c:\windows\system32\sppwinob.dll
2013-08-16 05:21 . 2013-09-10 19:39 81408 ----a-w- c:\windows\system32\setupcln.dll
2013-08-16 05:21 . 2013-09-10 19:39 120320 ----a-w- c:\windows\system32\sppc.dll
2013-08-16 05:20 . 2013-09-10 19:39 105984 ----a-w- c:\windows\system32\WinSetupUI.dll
2013-08-15 22:43 . 2013-09-10 19:39 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2013-08-15 22:43 . 2013-09-10 19:39 628736 ----a-w- c:\windows\SysWow64\wuapi.dll
2013-08-15 22:43 . 2013-09-10 19:39 84992 ----a-w- c:\windows\SysWow64\wudriver.dll
2013-08-15 22:43 . 2013-09-10 19:39 20992 ----a-w- c:\windows\SysWow64\wups.dll
2013-08-15 22:43 . 2013-09-10 19:39 126976 ----a-w- c:\windows\SysWow64\wuwebv.dll
2013-08-15 22:43 . 2013-09-10 19:39 562688 ----a-w- c:\windows\SysWow64\WSShared.dll
2013-08-15 22:43 . 2013-09-10 19:39 159232 ----a-w- c:\windows\SysWow64\WSSync.dll
2013-08-15 22:43 . 2013-09-10 19:39 143872 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.dll
2013-08-15 22:43 . 2013-09-10 19:39 167424 ----a-w- c:\windows\SysWow64\WSClient.dll
2013-08-15 22:43 . 2013-09-10 19:39 83968 ----a-w- c:\windows\SysWow64\OEMLicense.dll
2013-08-15 22:43 . 2013-09-10 19:39 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-08-15 22:42 . 2013-09-10 19:39 76800 ----a-w- c:\windows\SysWow64\setupcln.dll
2013-08-15 22:42 . 2013-09-10 19:39 91648 ----a-w- c:\windows\SysWow64\sppc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{D8278076-BC68-4484-9233-6E7F1628B56C}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll" [2013-11-06 129488]
.
[HKEY_CLASSES_ROOT\clsid\{d8278076-bc68-4484-9233-6e7f1628b56c}]
[HKEY_CLASSES_ROOT\TypeLib\{7C4EE486-5EA5-4683-8C23-BF520933BB5E}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{434D452D-5637-006A-76A7-7A786E7484D7}]
2013-11-06 19:07 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
2013-07-23 02:50 311536 ----a-w- c:\program files (x86)\Delta\delta\1.8.22.0\bh\delta.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{82E1477C-B154-48D3-9891-33D83C26BCD3}"= "c:\program files (x86)\Delta\delta\1.8.22.0\deltaTlbr.dll" [2013-07-23 300952]
"{434D452D-5637-006A-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport.dll" [2013-11-06 12240]
.
[HKEY_CLASSES_ROOT\clsid\{82e1477c-b154-48d3-9891-33d83c26bcd3}]
[HKEY_CLASSES_ROOT\delta.deltadskBnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[HKEY_CLASSES_ROOT\delta.deltadskBnd]
.
[HKEY_CLASSES_ROOT\clsid\{434d452d-5637-006a-76a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2013-05-31 802136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2012-04-19 217088]
"RemoteControl10"="c:\program files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe" [2012-03-29 91432]
"IntellingentTouchpad"="c:\program files (x86)\Lenovo\Intelligent Touchpad\IntelligentTouchpad.exe" [2012-07-23 673336]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-11-06 1707472]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-09-03 2237328]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
DRSpawner.lnk - c:\programdata\ASGvis\DRSpawner\DRSpawner.exe [2013-1-16 2080768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~3\BitGuard\271769~1.27\{C16C1~1\BitGuard.dll c:\windows\SysWOW64\nvinit.dll
.
R2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit;c:\program files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe;c:\program files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [x]
R2 WiseBootAssistant;Wise Boot Assistant;c:\program files (x86)\Wise\Wise Care 365\BootTime.exe;c:\program files (x86)\Wise\Wise Care 365\BootTime.exe [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 vmicheartbeat;Hyper-V Heartbeat Service;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 APNMCP;Ask Update Service;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 BitGuard;BitGuard;c:\programdata\BitGuard\2.7.1769.27\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe;c:\programdata\BitGuard\2.7.1769.27\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [x]
S2 CronService;Cron Service for Prey;c:\program files\Prey\platform\windows\cronsvc.exe;c:\program files\Prey\platform\windows\cronsvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\System32\drivers\btath_bus.sys;c:\windows\SYSNATIVE\drivers\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\System32\drivers\btath_hcrp.sys;c:\windows\SYSNATIVE\drivers\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\System32\drivers\btath_rcp.sys;c:\windows\SYSNATIVE\drivers\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 BthLEEnum;Bluetooth Low Energy Driver;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 IntcDAud;Intel(R) Zvuk pre obrazovky;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-24 17:56]
.
2013-11-13 c:\windows\Tasks\Wise Care 365.job
- c:\program files (x86)\Wise\Wise Care 365\WiseTray.exe [2013-07-22 12:57]
.
2013-07-24 c:\windows\Tasks\Wise Turbo Checker.job
- c:\program files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2013-07-22 10:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{434D452D-5637-006A-76A7-7A786E7484D7}]
2013-11-06 19:07 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{434D452D-5637-006A-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport_x64.dll" [2013-11-06 13776]
.
[HKEY_CLASSES_ROOT\CLSID\{434D452D-5637-006A-76A7-7A786E7484D7}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-08-03 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-08-03 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-08-03 440640]
"RtsFT"="RTFTrack.exe" [2012-08-27 6334096]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-08-10 13191824]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-08-06 1215632]
"BtTray"="c:\program files (x86)\Bluetooth Suite\BtTray.exe" [2012-08-11 764032]
"BtvStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2012-08-11 127616]
"OnekeyStudio"="c:\program files\Lenovo\Onekey Theater\OnekeyStudio.exe" [2012-08-10 4196432]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2012-11-04 17080376]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2012-11-04 191544]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-10-18 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-10-18 1063200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll c:\windows\system32\nvinitx.dll c:\windows\system32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.sk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{15126465-2056-7EBA-DF48-2839F1865607} - c:\programdata\safe saave\51e62877e6d86.dll
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynLenovoGestureMgr - c:\program files (x86)\Synaptics\SynTP\SynLenovoGestureMgr.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{924C3DC2-8E4E-432E-F973-9A2174A39774} - c:\programdata\safe saave\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-822971858-4240643665-2656738410-1002CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\SecuROM\License information*]
"datasecu"=hex:7d,b1,84,03,51,41,84,f7,2f,06,fe,d2,a1,d0,5c,42,68,a8,3e,94,b3,
20,7c,ae,12,96,55,30,d9,57,ac,bb,1b,f5,aa,b1,be,ed,e0,89,1f,d3,4b,3b,10,74,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Completion time: 2013-11-13 22:02:53
ComboFix-quarantined-files.txt 2013-11-13 21:02
.
Pre-Run: 346 913 787 904 bytes free
Post-Run: 346 756 124 672 bytes free
.
- - End Of File - - 6B83BB3DF09CD7D8C5787E03F02F4705

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosím o kontrolu

#2 Příspěvek od Rudy »

Proč spouštíte ComboFix, utilitu určenou pouze profesinálům? Hodláte si nabořit systém, příp nějakou aplikaci? Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

File::
c:\windows\system32\SETECF5.tmp
c:\windows\system32\SETFAF8.tmp
c:\windows\system32\SETFAA7.tmp
c:\windows\system32\SETCD0.tmp

Folder::
c:\program files (x86)\AskPartnerNetwork

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{D8278076-BC68-4484-9233-6E7F1628B56C}"=-
[-HKEY_CLASSES_ROOT\clsid\{d8278076-bc68-4484-9233-6e7f1628b56c}]
[-HKEY_CLASSES_ROOT\TypeLib\{7C4EE486-5EA5-4683-8C23-BF520933BB5E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{434D452D-5637-006A-76A7-7A786E7484D7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
[-HKEY_CLASSES_ROOT\clsid\{82e1477c-b154-48d3-9891-33d83c26bcd3}]
[-HKEY_CLASSES_ROOT\delta.deltadskBnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[-HKEY_CLASSES_ROOT\delta.deltadskBnd]
[-HKEY_CLASSES_ROOT\clsid\{434d452d-5637-006a-76a7-7a786e7484d7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ApnTBMon"=-
"SunJavaUpdateSched"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{434D452D-5637-006A-76A7-7A786E7484D7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{434D452D-5637-006A-76A7-7A786E7484D7}"=-

Regnull::
[HKEY_USERS\S-1-5-21-822971858-4240643665-2656738410-1002CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\SecuROM\License information*]

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej maší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

michal1995
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 13 lis 2013 22:17

Re: prosím o kontrolu

#3 Příspěvek od michal1995 »

a čo to spravi?

michal1995
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 13 lis 2013 22:17

Re: prosím o kontrolu

#4 Příspěvek od michal1995 »

urobil som ako ste mi kázali pretiahol som tú textovú zložku na combo fix


ComboFix 13-11-12.01 - Michal 14.11.2013 10:10:00.2.8 - x64
Microsoft Windows 8 6.2.9200.0.1250.421.1051.18.8048.6260 [GMT 1:00]
Running from: c:\users\Michal\Downloads\ComboFix.exe
Command switches used :: c:\users\Michal\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\SETCD0.tmp"
"c:\windows\system32\SETECF5.tmp"
"c:\windows\system32\SETFAA7.tmp"
"c:\windows\system32\SETFAF8.tmp"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\AskPartnerNetwork
c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\APNSetup.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport_x64.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1031.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1033.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1034.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1036.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1040.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1041.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1043.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1045.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1049.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\2070.mst
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\appdata\Mozilla\Firefox\Profiles\{DefaultProfilesFolder}\extensions\toolbar_CME-V7@apn.ask.com.xpi
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\AskToolbarInstaller-12.3.0_CME-V7.msi
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\AskToolbarInstaller-12.5.1_CME-V7.msi
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\AskToolbarInstaller-12.6.0_CME-V7.msi
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\AskToolbarInstaller-12.7.0_CME-V7.msi
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\{Crx_Version}\Toolbar.crx
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\ToolbarCR.crx
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\Update.xml
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport_x64.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\apnmcp.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\searchhook.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\ServiceLocator.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\SO.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\toolbar.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Toolbar.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\toolbar_x64.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\ToolbarPS.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\UpdateManager.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\{PartnerID}\config.xml
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\ask-search.xml
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\VNT\content.zip
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\VNT\vntldr.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\VNT\vntsrv.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\ServiceLocator.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\SO.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\toolbar.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\Toolbar.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\toolbar_x64.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\ToolbarPS.dll
c:\program files (x86)\AskPartnerNetwork\Toolbar\UpdateManager.exe
c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\ask-search.xml
c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\CME-V7\config.xml
c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
c:\windows\system32\SETCD0.tmp
c:\windows\system32\SETECF5.tmp
c:\windows\system32\SETFAA7.tmp
c:\windows\system32\SETFAF8.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_APNMCP
-------\Legacy_APNMCP
-------\Service_APNMCP
-------\Service_APNMCP
.
.
((((((((((((((((((((((((( Files Created from 2013-10-14 to 2013-11-14 )))))))))))))))))))))))))))))))
.
.
2013-11-14 09:17 . 2013-11-14 09:20 -------- d-----w- c:\users\Michal\AppData\Local\temp
2013-11-14 09:17 . 2013-11-14 09:17 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-11-14 09:17 . 2013-11-14 09:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-06 12:54 . 2013-11-06 12:54 342704 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10224.bin
2013-11-05 17:32 . 2013-11-05 17:32 -------- d-----w- c:\programdata\Package Cache
2013-10-31 08:22 . 2013-10-31 08:22 -------- d-----w- c:\windows\SysWow64\NV
2013-10-31 08:22 . 2013-10-31 08:22 -------- d-----w- c:\windows\system32\NV
2013-10-31 08:17 . 2013-10-23 10:30 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-10-31 08:17 . 2013-10-23 10:30 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-10-31 08:17 . 2013-10-23 10:30 9480328 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-10-31 08:17 . 2013-10-23 10:30 655136 ----a-w- c:\windows\system32\NvIFR64.dll
2013-10-31 08:17 . 2013-10-23 10:30 560416 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-10-31 08:17 . 2013-10-23 10:30 32544 ----a-w- c:\windows\system32\drivers\nvpciflt.sys
2013-10-31 08:17 . 2013-10-23 10:30 317472 ----a-w- c:\windows\system32\nvoglshim64.dll
2013-10-31 08:17 . 2013-10-23 10:30 30344480 ----a-w- c:\windows\system32\nvoglv64.dll
2013-10-31 08:17 . 2013-10-23 10:30 266984 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2013-10-31 08:17 . 2013-10-23 10:30 22933792 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-10-31 08:17 . 2013-10-23 10:30 12572960 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-10-31 08:17 . 2013-10-23 10:30 11374520 ----a-w- c:\windows\system32\nvopencl.dll
2013-10-28 19:59 . 2013-10-28 19:59 -------- d-----w- c:\users\Michal\AppData\Local\Aspyr
2013-10-28 19:57 . 2013-10-28 19:57 -------- d-----w- c:\program files (x86)\Sigma Production Inc
2013-10-28 19:55 . 2013-10-18 01:36 1063200 ----a-w- c:\windows\system32\nvspcap64.dll
2013-10-28 19:55 . 2013-10-18 01:36 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-10-28 19:54 . 2013-09-27 23:01 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-10-28 19:54 . 2013-09-27 23:01 28960 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-10-28 19:31 . 2013-10-28 19:31 -------- d-----w- c:\program files (x86)\Aspyr
2013-10-26 19:38 . 2013-10-26 19:38 -------- d-----w- c:\program files (x86)\Common Files\myCuteBuddy
2013-10-26 19:37 . 2013-10-26 19:38 -------- d-----w- c:\program files (x86)\My Cute Buddy
2013-10-26 19:36 . 2013-10-31 08:06 -------- d-----w- c:\program files (x86)\Iminent
2013-10-25 17:37 . 2013-10-25 17:37 -------- d-----w- c:\users\Michal\AppData\Roaming\Adobe Mini Bridge CS5
2013-10-25 17:37 . 2013-10-25 17:37 -------- d-----w- c:\users\Michal\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-10-24 14:15 . 2013-10-24 14:15 -------- d-----w- c:\users\Michal\AppData\Roaming\Unity
2013-10-23 02:02 . 2013-10-23 02:02 589600 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-10-21 18:11 . 2013-10-16 00:48 1884448 ----a-w- c:\windows\system32\nvdispco6433158.dll
2013-10-21 18:11 . 2013-10-16 00:48 1511712 ----a-w- c:\windows\system32\nvdispgenco6433158.dll
2013-10-17 18:23 . 2013-10-17 18:23 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-17 18:23 . 2013-10-17 18:23 -------- d-----w- c:\program files (x86)\Java
2013-10-17 18:18 . 2013-10-17 18:18 312744 ----a-w- c:\windows\system32\javaws.exe
2013-10-17 18:18 . 2013-10-17 18:18 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-10-17 18:18 . 2013-10-17 18:18 189352 ----a-w- c:\windows\system32\javaw.exe
2013-10-17 18:18 . 2013-10-17 18:18 189352 ----a-w- c:\windows\system32\java.exe
2013-10-17 18:18 . 2013-10-17 18:18 -------- d-----w- c:\program files\Java
2013-10-16 11:34 . 2013-10-16 11:34 -------- d-----w- c:\users\Michal\AppData\Roaming\Opera Software
2013-10-16 11:34 . 2013-10-16 11:34 -------- d-----w- c:\users\Michal\AppData\Local\Opera Software
2013-10-16 11:30 . 2013-08-03 06:40 566784 ----a-w- c:\windows\system32\wvc.dll
2013-10-16 11:30 . 2013-08-03 06:40 1374208 ----a-w- c:\windows\system32\wdc.dll
2013-10-16 11:30 . 2013-08-03 06:40 462336 ----a-w- c:\windows\system32\sysmon.ocx
2013-10-16 11:30 . 2013-08-03 05:13 1245696 ----a-w- c:\windows\SysWow64\wdc.dll
2013-10-16 11:30 . 2013-08-03 05:14 399360 ----a-w- c:\windows\SysWow64\sysmon.ocx
2013-10-16 11:30 . 2013-08-03 05:13 437248 ----a-w- c:\windows\SysWow64\wvc.dll
2013-10-16 11:30 . 2013-08-02 06:28 19758080 ----a-w- c:\windows\system32\shell32.dll
2013-10-16 11:30 . 2013-08-02 06:28 10116608 ----a-w- c:\windows\system32\twinui.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-10 18:23 . 2013-02-21 11:34 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-11-10 18:23 . 2013-02-21 11:34 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-11-10 18:23 . 2012-12-28 19:12 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-10-23 10:30 . 2012-11-03 23:34 3067560 ----a-w- c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2012-11-03 23:34 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2012-11-03 23:34 18199872 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-10-23 10:30 . 2012-11-03 23:34 168616 ----a-w- c:\windows\system32\nvinitx.dll
2013-10-23 10:30 . 2012-11-03 23:34 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-10-23 10:30 . 2012-11-03 23:34 1435504 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-10-23 10:30 . 2012-11-03 23:34 141336 ----a-w- c:\windows\SysWow64\nvinit.dll
2013-10-23 10:30 . 2012-11-03 23:34 1241376 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2013-10-23 08:20 . 2012-11-03 23:34 6669600 ----a-w- c:\windows\system32\nvcpl.dll
2013-10-23 08:20 . 2012-11-03 23:34 3489568 ----a-w- c:\windows\system32\nvsvc64.dll
2013-10-23 08:20 . 2012-11-03 23:34 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-10-23 08:20 . 2012-11-03 23:34 67072 ----a-w- c:\windows\system32\nv3dappshextr.dll
2013-10-23 08:20 . 2012-11-03 23:34 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-10-23 08:20 . 2012-11-03 23:34 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-10-23 08:20 . 2012-11-03 23:34 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-10-23 08:20 . 2012-11-03 23:34 1064224 ----a-w- c:\windows\system32\nv3dappshext.dll
2013-10-23 08:20 . 2012-11-03 23:34 597280 ----a-w- c:\windows\SysWow64\oemdspif.dll
2013-10-23 08:20 . 2012-11-03 23:34 3426956 ----a-w- c:\windows\system32\nvcoproc.bin
2013-10-08 21:44 . 2012-12-24 22:09 80541720 ----a-w- c:\windows\system32\MRT.exe
2013-10-02 01:38 . 2013-09-12 17:51 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-27 23:01 . 2013-08-02 06:01 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-09-25 05:25 . 2013-03-18 16:52 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-09-22 23:28 . 2013-10-08 21:12 1767936 ----a-w- c:\windows\SysWow64\wininet.dll
2013-09-22 23:27 . 2013-10-08 21:11 2876928 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-09-22 22:55 . 2013-10-08 21:12 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2013-09-22 22:55 . 2013-10-08 21:12 2241024 ----a-w- c:\windows\system32\wininet.dll
2013-09-22 22:55 . 2013-10-08 21:12 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-09-22 22:54 . 2013-10-08 21:12 603136 ----a-w- c:\windows\system32\msfeeds.dll
2013-09-22 22:54 . 2013-10-08 21:12 19252224 ----a-w- c:\windows\system32\mshtml.dll
2013-09-22 22:54 . 2013-10-08 21:12 855552 ----a-w- c:\windows\system32\jscript.dll
2013-09-22 22:54 . 2013-10-08 21:11 3959296 ----a-w- c:\windows\system32\jscript9.dll
2013-09-22 22:54 . 2013-10-08 21:12 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-09-22 22:54 . 2013-10-08 21:11 2647552 ----a-w- c:\windows\system32\iertutil.dll
2013-09-12 08:58 . 2013-09-23 17:31 1884448 ----a-w- c:\windows\system32\nvdispco6432723.dll
2013-09-12 08:58 . 2013-09-23 17:31 1511712 ----a-w- c:\windows\system32\nvdispgenco6432723.dll
2013-08-30 07:48 . 2013-03-06 20:30 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2013-03-06 20:30 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2013-03-06 20:30 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2012-12-28 14:27 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2012-12-28 14:27 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2012-12-28 14:27 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2012-12-28 14:27 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2012-12-28 14:27 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2012-12-28 14:27 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2012-12-28 14:27 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-23 05:11 . 2013-10-08 21:10 4040192 ----a-w- c:\windows\system32\win32k.sys
2013-08-20 13:32 . 2013-08-02 06:01 29984 ----a-w- c:\windows\system32\SET85C6.tmp
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{15126465-2056-7EBA-DF48-2839F1865607}]
c:\programdata\safe saave\51e62877e6d86.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
2013-07-23 02:50 311536 ----a-w- c:\program files (x86)\Delta\delta\1.8.22.0\bh\delta.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2013-05-31 802136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2012-04-19 217088]
"RemoteControl10"="c:\program files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe" [2012-03-29 91432]
"IntellingentTouchpad"="c:\program files (x86)\Lenovo\Intelligent Touchpad\IntelligentTouchpad.exe" [2012-07-23 673336]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-09-03 2237328]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
DRSpawner.lnk - c:\programdata\ASGvis\DRSpawner\DRSpawner.exe [2013-1-16 2080768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~3\BitGuard\271769~1.27\{C16C1~1\BitGuard.dll c:\windows\SysWOW64\nvinit.dll
.
R2 WiseBootAssistant;Wise Boot Assistant;c:\program files (x86)\Wise\Wise Care 365\BootTime.exe;c:\program files (x86)\Wise\Wise Care 365\BootTime.exe [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 vmicheartbeat;Hyper-V Heartbeat Service;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 CronService;Cron Service for Prey;c:\program files\Prey\platform\windows\cronsvc.exe;c:\program files\Prey\platform\windows\cronsvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit;c:\program files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe;c:\program files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\System32\drivers\btath_bus.sys;c:\windows\SYSNATIVE\drivers\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\System32\drivers\btath_hcrp.sys;c:\windows\SYSNATIVE\drivers\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\System32\drivers\btath_rcp.sys;c:\windows\SYSNATIVE\drivers\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 BthLEEnum;Bluetooth Low Energy Driver;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 IntcDAud;Intel(R) Zvuk pre obrazovky;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-24 17:56]
.
2013-11-14 c:\windows\Tasks\Wise Care 365.job
- c:\program files (x86)\Wise\Wise Care 365\WiseTray.exe [2013-07-22 12:57]
.
2013-07-24 c:\windows\Tasks\Wise Turbo Checker.job
- c:\program files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2013-07-22 10:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2013-08-30 08:01 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-08-03 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-08-03 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-08-03 440640]
"RtsFT"="RTFTrack.exe" [2012-08-27 6334096]
"SynLenovoGestureMgr"="c:\program files (x86)\Synaptics\SynTP\SynLenovoGestureMgr.exe" [BU]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-08-10 13191824]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-08-06 1215632]
"BtTray"="c:\program files (x86)\Bluetooth Suite\BtTray.exe" [2012-08-11 764032]
"BtvStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2012-08-11 127616]
"OnekeyStudio"="c:\program files\Lenovo\Onekey Theater\OnekeyStudio.exe" [2012-08-10 4196432]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2012-11-04 17080376]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2012-11-04 191544]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-10-18 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-10-18 1063200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~3\BitGuard\271769~1.27\{C16C1~1\loader.dll c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.sk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{434D452D-5637-006A-76A7-7A786E7484D7} - c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Passport.dll
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{924C3DC2-8E4E-432E-F973-9A2174A39774} - c:\programdata\safe saave\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-822971858-4240643665-2656738410-1002CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\SecuROM\License information*]
"datasecu"=hex:7d,b1,84,03,51,41,84,f7,2f,06,fe,d2,a1,d0,5c,42,68,a8,3e,94,b3,
20,7c,ae,12,96,55,30,d9,57,ac,bb,1b,f5,aa,b1,be,ed,e0,89,1f,d3,4b,3b,10,74,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Lenovo\YouCam\YCMMirage.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2013-11-14 10:25:34 - machine was rebooted
ComboFix-quarantined-files.txt 2013-11-14 09:25
ComboFix2.txt 2013-11-13 21:02
.
Pre-Run: 341 638 258 688 bytes free
Post-Run: 341 137 453 056 bytes free
.
- - End Of File - - EA146E62D3A32D26BC9E1C008FB749F2

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosím o kontrolu

#5 Příspěvek od Rudy »

Vše smazáno.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

michal1995
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 13 lis 2013 22:17

Re: prosím o kontrolu

#6 Příspěvek od michal1995 »

a môžem tento spôsob využívať ked budem mať vírus?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosím o kontrolu

#7 Příspěvek od Rudy »

Nemůžete, neboť CF je utilita určená pouze profesionálům, kteří umí napsat skript. Naše fórum má akreditaci k jejímu používání přímo od autora. Když si dáte požadavek k nám, vždy vám PC odvirujeme. Ne vždy je použití CF vhodné. Ostatní skenery, které tu používáme, jsou každému k dispozici. CF odinstalujte pomocí T-Cleaneru: http://vyosek.ic.cz/pro_usery/T-Cleaner.exe .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět