
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Zpomalené PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpomalené PC
Dobrý den, poslední dobou mám zpomalené pC hlavně při startu systému, problém s přehráváním videa na jakýchkoliv nternetových stránkách, občas nefungují komunuikační programy (skype apod.)
Zde výpis z RSIT a výpis z Combofixu
Logfile of random's system information tool 1.10 (written by random/random)
Run by 7 at 2014-11-29 11:40:14
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 73 GB (48%) free of 153 GB
Total RAM: 2047 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:40:22, on 29.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.17148)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\7\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\7.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 5047 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
"faststartff@gmail.com"=C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default\extensions\faststartff@gmail.com
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.239 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-09-15 767200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-11-29 11:40:14 ----D---- C:\rsit
2014-11-29 11:40:14 ----D---- C:\Program Files (x86)\trend micro
2014-11-29 11:30:12 ----SHD---- C:\$RECYCLE.BIN
2014-11-29 11:30:05 ----D---- C:\Windows\temp
2014-11-29 11:30:03 ----A---- C:\ComboFix.txt
2014-11-29 11:16:18 ----A---- C:\Windows\zip.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWSC.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWREG.exe
2014-11-29 11:16:18 ----A---- C:\Windows\sed.exe
2014-11-29 11:16:18 ----A---- C:\Windows\PEV.exe
2014-11-29 11:16:18 ----A---- C:\Windows\NIRCMD.exe
2014-11-29 11:16:18 ----A---- C:\Windows\MBR.exe
2014-11-29 11:16:18 ----A---- C:\Windows\grep.exe
2014-11-29 11:15:38 ----D---- C:\Qoobox
2014-11-29 11:15:03 ----D---- C:\Windows\erdnt
2014-11-23 00:27:29 ----D---- C:\ProgramData\ATI
2014-11-23 00:24:23 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:12:19 ----D---- C:\Program Files (x86)\Common Files\Skype
2014-11-18 21:12:18 ----RD---- C:\Program Files (x86)\Skype
2014-11-12 16:49:39 ----D---- C:\Users\7\AppData\Roaming\fltk.org
2014-11-12 16:49:14 ----D---- C:\Users\7\AppData\Roaming\flightgear.org
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\msaudite.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\adtschema.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\schannel.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\wdigest.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\credssp.dll
2014-11-12 11:22:12 ----A---- C:\Windows\SysWOW64\packager.dll
2014-11-12 10:15:19 ----A---- C:\Windows\SysWOW64\msi.dll
2014-11-12 10:14:41 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 10:14:39 ----A---- C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 10:14:36 ----A---- C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3.dll
2014-11-12 10:14:20 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-11-12 10:14:16 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-11-12 10:14:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2014-11-12 10:14:09 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-11-11 11:17:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-09 20:51:05 ----D---- C:\Users\7\AppData\Roaming\Quake3
2014-11-09 20:46:07 ----D---- C:\Program Files (x86)\ioQuake3&TA
2014-11-03 17:48:32 ----D---- C:\Program Files (x86)\MarkAny
2014-11-03 17:47:35 ----D---- C:\Users\7\AppData\Roaming\Samsung
2014-11-03 17:45:56 ----A---- C:\Windows\SysWOW64\secman.dll
2014-11-03 17:45:50 ----A---- C:\Windows\SysWOW64\Redemption.dll
2014-11-03 17:44:05 ----D---- C:\ProgramData\Samsung
2014-11-03 17:44:05 ----D---- C:\Program Files (x86)\Samsung
======List of files/folders modified in the last 1 month======
2014-11-29 11:40:14 ----RD---- C:\Program Files (x86)
2014-11-29 11:30:05 ----D---- C:\Windows
2014-11-29 11:28:18 ----D---- C:\Users\7\AppData\Roaming\Skype
2014-11-29 11:26:39 ----A---- C:\Windows\system.ini
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64\drivers
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64
2014-11-29 11:23:13 ----D---- C:\Windows\AppPatch
2014-11-29 11:23:11 ----D---- C:\Program Files (x86)\Common Files
2014-11-29 11:16:53 ----SHD---- C:\System Volume Information
2014-11-29 11:16:23 ----D---- C:\Windows\Prefetch
2014-11-28 14:14:34 ----D---- C:\Windows\inf
2014-11-25 22:49:12 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:28:35 ----D---- C:\Users\7\AppData\Roaming\uTorrent
2014-11-23 16:22:42 ----SD---- C:\Users\7\AppData\Roaming\Microsoft
2014-11-23 16:22:41 ----D---- C:\ProgramData\Microsoft Help
2014-11-23 10:43:10 ----D---- C:\Windows\Microsoft.NET
2014-11-23 00:46:21 ----D---- C:\Windows\winsxs
2014-11-23 00:36:18 ----SHD---- C:\Windows\Installer
2014-11-23 00:36:17 ----D---- C:\Config.Msi
2014-11-23 00:35:07 ----D---- C:\Windows\System32
2014-11-23 00:33:33 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2014-11-23 00:29:49 ----D---- C:\ProgramData\AMD
2014-11-23 00:27:29 ----D---- C:\ProgramData
2014-11-18 21:12:16 ----D---- C:\ProgramData\Skype
2014-11-18 16:11:12 ----D---- C:\Windows\Panther
2014-11-18 16:11:12 ----D---- C:\Windows\debug
2014-11-12 17:08:22 ----RD---- C:\Program Files
2014-11-12 12:54:07 ----D---- C:\Windows\rescache
2014-11-12 12:00:28 ----RSD---- C:\Windows\assembly
2014-11-12 11:49:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-11-12 11:11:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-08 11:04:26 ----SD---- C:\ProgramData\Microsoft
2014-11-06 20:19:12 ----D---- C:\Windows\Tasks
2014-11-03 17:45:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys []
S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 344064]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2013-08-19 1337240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-25 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetPipeActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetTcpActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
-----------------EOF-----------------
COMBOFIX
ComboFix 14-11-25.01 - 7 29.11.2014 11:19:42.1.1 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2047.913 [GMT 1:00]
Spuštěný z: c:\users\7\Desktop\ComboFix.exe
AV: ESET Smart Security 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-10-28 do 2014-11-29 )))))))))))))))))))))))))))))))
.
.
2014-11-29 10:26 . 2014-11-29 10:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-11-28 11:58 . 2014-11-02 04:20 11632448 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F945997B-87E1-4D44-9993-CAA128717848}\mpengine.dll
2014-11-22 23:27 . 2014-11-22 23:27 -------- d-----w- c:\programdata\ATI
2014-11-22 23:24 . 2014-11-22 23:24 -------- d-----w- c:\program files (x86)\ATI Technologies
2014-11-22 17:14 . 2014-11-22 17:14 -------- d-----w- c:\users\7\AppData\Local\Microsoft_Corporation
2014-11-19 15:57 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
2014-11-19 15:57 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-11-19 15:57 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2014-11-19 15:57 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-11-18 20:12 . 2014-11-18 20:12 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-11-18 20:12 . 2014-11-18 20:12 -------- d-----r- c:\program files (x86)\Skype
2014-11-12 15:52 . 2014-11-12 15:52 -------- d-----w- c:\users\7\AppData\Local\CrashRpt
2014-11-12 15:49 . 2014-11-12 15:49 -------- d-----w- c:\users\7\AppData\Roaming\fltk.org
2014-11-12 15:49 . 2014-11-12 16:07 -------- d-----w- c:\users\7\AppData\Roaming\flightgear.org
2014-11-12 10:22 . 2014-10-25 01:57 77824 ----a-w- c:\windows\system32\packager.dll
2014-11-12 10:22 . 2014-10-25 01:32 67584 ----a-w- c:\windows\SysWow64\packager.dll
2014-11-12 10:22 . 2014-10-10 00:57 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-11-12 09:15 . 2014-10-14 02:13 3241984 ----a-w- c:\windows\system32\msi.dll
2014-11-12 09:15 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\SysWow64\msi.dll
2014-11-09 19:51 . 2014-11-10 14:25 -------- d-----w- c:\users\7\AppData\Roaming\Quake3
2014-11-09 19:46 . 2014-11-09 19:48 -------- d-----w- c:\program files (x86)\ioQuake3&TA
2014-11-03 16:51 . 2014-06-16 06:01 206080 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2014-11-03 16:51 . 2014-06-16 06:01 110336 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2014-11-03 16:48 . 2014-11-03 16:48 -------- d-----w- c:\program files (x86)\MarkAny
2014-11-03 16:47 . 2014-11-03 16:47 -------- d-----w- c:\users\7\AppData\Local\Samsung
2014-11-03 16:47 . 2014-11-03 16:47 -------- d-----w- c:\users\7\AppData\Roaming\Samsung
2014-11-03 16:45 . 2014-04-30 18:43 144664 ----a-w- c:\windows\SysWow64\secman.dll
2014-11-03 16:45 . 2014-04-30 18:43 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2014-11-03 16:44 . 2014-11-03 16:46 -------- d-----w- c:\program files (x86)\Samsung
2014-11-03 16:44 . 2014-11-03 16:46 -------- d-----w- c:\programdata\Samsung
2014-11-03 16:42 . 2014-11-03 16:42 -------- d-----w- c:\users\7\AppData\Local\Downloaded Installations
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-25 21:49 . 2014-10-16 18:22 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-25 21:49 . 2014-10-16 18:22 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-11-12 00:19 . 2014-10-16 19:04 103374192 ----a-w- c:\windows\system32\MRT.exe
2014-11-04 13:30 . 2014-10-16 18:00 275080 ------w- c:\windows\system32\MpSigStub.exe
2014-10-26 21:43 . 2014-10-26 21:43 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-10-26 21:43 . 2014-10-26 21:43 226304 ----a-w- c:\windows\system32\elshyph.dll
2014-10-26 21:43 . 2014-10-26 21:43 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-10-26 21:43 . 2014-10-26 21:43 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2014-10-26 21:43 . 2014-10-26 21:43 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-10-26 21:43 . 2014-10-26 21:43 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-10-26 21:43 . 2014-10-26 21:43 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2014-10-26 21:43 . 2014-10-26 21:43 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-10-26 21:43 . 2014-10-26 21:43 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-10-26 21:43 . 2014-10-26 21:43 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2014-10-26 21:43 . 2014-10-26 21:43 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-10-26 21:43 . 2014-10-26 21:43 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-10-26 21:43 . 2014-10-26 21:43 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-10-26 21:43 . 2014-10-26 21:43 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-10-26 21:43 . 2014-10-26 21:43 361984 ----a-w- c:\windows\SysWow64\html.iec
2014-10-26 21:43 . 2014-10-26 21:43 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-10-26 21:43 . 2014-10-26 21:43 216064 ----a-w- c:\windows\system32\msls31.dll
2014-10-26 21:43 . 2014-10-26 21:43 441856 ----a-w- c:\windows\system32\html.iec
2014-10-26 21:43 . 2014-10-26 21:43 81408 ----a-w- c:\windows\system32\icardie.dll
2014-10-26 21:43 . 2014-10-26 21:43 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2014-10-26 21:43 . 2014-10-26 21:43 235008 ----a-w- c:\windows\system32\url.dll
2014-10-26 21:43 . 2014-10-26 21:43 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2014-10-26 21:43 . 2014-10-26 21:43 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-10-26 21:43 . 2014-10-26 21:43 247296 ----a-w- c:\windows\system32\webcheck.dll
2014-10-26 21:43 . 2014-10-26 21:43 27648 ----a-w- c:\windows\system32\licmgr10.dll
2014-10-26 21:43 . 2014-10-26 21:42 102912 ----a-w- c:\windows\system32\inseng.dll
2014-10-26 21:42 . 2014-10-26 21:42 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-10-26 21:42 . 2014-10-26 21:42 144896 ----a-w- c:\windows\system32\wextract.exe
2014-10-26 21:42 . 2014-10-26 21:42 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2014-10-26 21:42 . 2014-10-26 21:42 62976 ----a-w- c:\windows\system32\pngfilt.dll
2014-10-26 21:42 . 2014-10-26 21:42 149504 ----a-w- c:\windows\system32\occache.dll
2014-10-26 21:42 . 2014-10-26 21:42 13824 ----a-w- c:\windows\system32\mshta.exe
2014-10-26 21:42 . 2014-10-26 21:42 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-10-26 21:42 . 2014-10-26 21:42 51200 ----a-w- c:\windows\system32\imgutil.dll
2014-10-26 21:42 . 2014-10-26 21:42 136192 ----a-w- c:\windows\system32\iepeers.dll
2014-10-26 21:42 . 2014-10-26 21:42 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-10-26 21:42 . 2014-10-26 21:42 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2014-10-26 21:42 . 2014-10-26 21:42 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-10-26 21:42 . 2014-10-26 21:42 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-10-26 21:42 . 2014-10-26 21:42 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-10-26 19:39 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2014-10-26 19:39 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-10-17 19:45 . 2014-10-17 19:45 859648 ----a-w- c:\windows\system32\tdh.dll
2014-10-17 19:45 . 2014-10-17 19:45 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-10-17 19:45 . 2014-10-17 19:45 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-10-17 19:45 . 2014-10-17 19:45 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-10-17 19:45 . 2014-10-17 19:45 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-10-17 19:45 . 2014-10-17 19:45 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-10-17 19:44 . 2014-10-17 19:44 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-10-17 19:44 . 2014-10-17 19:44 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-10-17 19:33 . 2014-10-17 19:33 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2014-10-17 19:33 . 2014-10-17 19:33 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2014-10-17 19:33 . 2014-10-17 19:33 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2014-10-17 19:33 . 2014-10-17 19:33 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-10-17 19:33 . 2014-10-17 19:33 363008 ----a-w- c:\windows\system32\dxgi.dll
2014-10-17 19:33 . 2014-10-17 19:33 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2014-10-17 19:33 . 2014-10-17 19:33 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2014-10-17 19:33 . 2014-10-17 19:33 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2014-10-17 19:33 . 2014-10-17 19:33 1175552 ----a-w- c:\windows\system32\FntCache.dll
2014-10-17 19:33 . 2014-10-17 19:33 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
2014-10-17 19:33 . 2014-10-17 19:33 1643520 ----a-w- c:\windows\system32\DWrite.dll
2014-10-17 19:33 . 2014-10-17 19:33 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-10-17 19:33 . 2014-10-17 19:33 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-10-17 19:33 . 2014-10-17 19:33 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-10-17 19:33 . 2014-10-17 19:33 296960 ----a-w- c:\windows\system32\d3d10core.dll
2014-10-17 19:33 . 2014-10-17 19:33 1238528 ----a-w- c:\windows\system32\d3d10.dll
2014-10-17 19:33 . 2014-10-17 19:33 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-10-17 19:33 . 2014-10-17 19:33 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-10-17 19:33 . 2014-10-17 19:33 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2014-10-17 19:33 . 2014-10-17 19:33 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-10-17 19:33 . 2014-10-17 19:33 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2014-10-17 19:33 . 2014-10-17 19:33 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2014-10-17 19:33 . 2014-10-17 19:33 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2014-10-17 19:29 . 2014-10-17 19:29 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-10-17 19:29 . 2014-10-17 19:29 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-10-16 18:45 . 2014-10-16 18:45 319456 ----a-w- c:\windows\DIFxAPI.dll
2014-09-25 02:08 . 2014-10-18 13:05 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-09-25 01:40 . 2014-10-18 13:05 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-09-15 767200]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-11-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-16 21:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2013-08-19 5617432]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mDefault_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1413487354&from=cvs&uid=126614527_331763_DC6589E3&q={searchTerms}
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1413487354&from=cvs&uid=126614527_331763_DC6589E3&q={searchTerms}
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 83.240.0.135 83.240.0.214
FF - ProfilePath - c:\users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default\
FF - prefs.js: browser.startup.homepage - www.centrum.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-11-29 11:30:02
ComboFix-quarantined-files.txt 2014-11-29 10:30
.
Před spuštěním: Volných bajtů: 76 635 041 792
Po spuštění: Volných bajtů: 76 217 544 704
.
- - End Of File - - B4D25810E68CBD1140691AE44243A8BE
A36C5E4F47E84449FF07ED3517B43A31
Zde výpis z RSIT a výpis z Combofixu
Logfile of random's system information tool 1.10 (written by random/random)
Run by 7 at 2014-11-29 11:40:14
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 73 GB (48%) free of 153 GB
Total RAM: 2047 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:40:22, on 29.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.17148)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\7\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\7.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 5047 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
"faststartff@gmail.com"=C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default\extensions\faststartff@gmail.com
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.239 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-09-15 767200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-11-29 11:40:14 ----D---- C:\rsit
2014-11-29 11:40:14 ----D---- C:\Program Files (x86)\trend micro
2014-11-29 11:30:12 ----SHD---- C:\$RECYCLE.BIN
2014-11-29 11:30:05 ----D---- C:\Windows\temp
2014-11-29 11:30:03 ----A---- C:\ComboFix.txt
2014-11-29 11:16:18 ----A---- C:\Windows\zip.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWSC.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWREG.exe
2014-11-29 11:16:18 ----A---- C:\Windows\sed.exe
2014-11-29 11:16:18 ----A---- C:\Windows\PEV.exe
2014-11-29 11:16:18 ----A---- C:\Windows\NIRCMD.exe
2014-11-29 11:16:18 ----A---- C:\Windows\MBR.exe
2014-11-29 11:16:18 ----A---- C:\Windows\grep.exe
2014-11-29 11:15:38 ----D---- C:\Qoobox
2014-11-29 11:15:03 ----D---- C:\Windows\erdnt
2014-11-23 00:27:29 ----D---- C:\ProgramData\ATI
2014-11-23 00:24:23 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:12:19 ----D---- C:\Program Files (x86)\Common Files\Skype
2014-11-18 21:12:18 ----RD---- C:\Program Files (x86)\Skype
2014-11-12 16:49:39 ----D---- C:\Users\7\AppData\Roaming\fltk.org
2014-11-12 16:49:14 ----D---- C:\Users\7\AppData\Roaming\flightgear.org
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\msaudite.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\adtschema.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\schannel.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\wdigest.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\credssp.dll
2014-11-12 11:22:12 ----A---- C:\Windows\SysWOW64\packager.dll
2014-11-12 10:15:19 ----A---- C:\Windows\SysWOW64\msi.dll
2014-11-12 10:14:41 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 10:14:39 ----A---- C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 10:14:36 ----A---- C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3.dll
2014-11-12 10:14:20 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-11-12 10:14:16 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-11-12 10:14:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2014-11-12 10:14:09 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-11-11 11:17:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-09 20:51:05 ----D---- C:\Users\7\AppData\Roaming\Quake3
2014-11-09 20:46:07 ----D---- C:\Program Files (x86)\ioQuake3&TA
2014-11-03 17:48:32 ----D---- C:\Program Files (x86)\MarkAny
2014-11-03 17:47:35 ----D---- C:\Users\7\AppData\Roaming\Samsung
2014-11-03 17:45:56 ----A---- C:\Windows\SysWOW64\secman.dll
2014-11-03 17:45:50 ----A---- C:\Windows\SysWOW64\Redemption.dll
2014-11-03 17:44:05 ----D---- C:\ProgramData\Samsung
2014-11-03 17:44:05 ----D---- C:\Program Files (x86)\Samsung
======List of files/folders modified in the last 1 month======
2014-11-29 11:40:14 ----RD---- C:\Program Files (x86)
2014-11-29 11:30:05 ----D---- C:\Windows
2014-11-29 11:28:18 ----D---- C:\Users\7\AppData\Roaming\Skype
2014-11-29 11:26:39 ----A---- C:\Windows\system.ini
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64\drivers
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64
2014-11-29 11:23:13 ----D---- C:\Windows\AppPatch
2014-11-29 11:23:11 ----D---- C:\Program Files (x86)\Common Files
2014-11-29 11:16:53 ----SHD---- C:\System Volume Information
2014-11-29 11:16:23 ----D---- C:\Windows\Prefetch
2014-11-28 14:14:34 ----D---- C:\Windows\inf
2014-11-25 22:49:12 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:28:35 ----D---- C:\Users\7\AppData\Roaming\uTorrent
2014-11-23 16:22:42 ----SD---- C:\Users\7\AppData\Roaming\Microsoft
2014-11-23 16:22:41 ----D---- C:\ProgramData\Microsoft Help
2014-11-23 10:43:10 ----D---- C:\Windows\Microsoft.NET
2014-11-23 00:46:21 ----D---- C:\Windows\winsxs
2014-11-23 00:36:18 ----SHD---- C:\Windows\Installer
2014-11-23 00:36:17 ----D---- C:\Config.Msi
2014-11-23 00:35:07 ----D---- C:\Windows\System32
2014-11-23 00:33:33 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2014-11-23 00:29:49 ----D---- C:\ProgramData\AMD
2014-11-23 00:27:29 ----D---- C:\ProgramData
2014-11-18 21:12:16 ----D---- C:\ProgramData\Skype
2014-11-18 16:11:12 ----D---- C:\Windows\Panther
2014-11-18 16:11:12 ----D---- C:\Windows\debug
2014-11-12 17:08:22 ----RD---- C:\Program Files
2014-11-12 12:54:07 ----D---- C:\Windows\rescache
2014-11-12 12:00:28 ----RSD---- C:\Windows\assembly
2014-11-12 11:49:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-11-12 11:11:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-08 11:04:26 ----SD---- C:\ProgramData\Microsoft
2014-11-06 20:19:12 ----D---- C:\Windows\Tasks
2014-11-03 17:45:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys []
S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 344064]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2013-08-19 1337240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-25 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetPipeActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetTcpActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
-----------------EOF-----------------
COMBOFIX
ComboFix 14-11-25.01 - 7 29.11.2014 11:19:42.1.1 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2047.913 [GMT 1:00]
Spuštěný z: c:\users\7\Desktop\ComboFix.exe
AV: ESET Smart Security 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-10-28 do 2014-11-29 )))))))))))))))))))))))))))))))
.
.
2014-11-29 10:26 . 2014-11-29 10:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-11-28 11:58 . 2014-11-02 04:20 11632448 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F945997B-87E1-4D44-9993-CAA128717848}\mpengine.dll
2014-11-22 23:27 . 2014-11-22 23:27 -------- d-----w- c:\programdata\ATI
2014-11-22 23:24 . 2014-11-22 23:24 -------- d-----w- c:\program files (x86)\ATI Technologies
2014-11-22 17:14 . 2014-11-22 17:14 -------- d-----w- c:\users\7\AppData\Local\Microsoft_Corporation
2014-11-19 15:57 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
2014-11-19 15:57 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-11-19 15:57 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2014-11-19 15:57 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-11-18 20:12 . 2014-11-18 20:12 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-11-18 20:12 . 2014-11-18 20:12 -------- d-----r- c:\program files (x86)\Skype
2014-11-12 15:52 . 2014-11-12 15:52 -------- d-----w- c:\users\7\AppData\Local\CrashRpt
2014-11-12 15:49 . 2014-11-12 15:49 -------- d-----w- c:\users\7\AppData\Roaming\fltk.org
2014-11-12 15:49 . 2014-11-12 16:07 -------- d-----w- c:\users\7\AppData\Roaming\flightgear.org
2014-11-12 10:22 . 2014-10-25 01:57 77824 ----a-w- c:\windows\system32\packager.dll
2014-11-12 10:22 . 2014-10-25 01:32 67584 ----a-w- c:\windows\SysWow64\packager.dll
2014-11-12 10:22 . 2014-10-10 00:57 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-11-12 09:15 . 2014-10-14 02:13 3241984 ----a-w- c:\windows\system32\msi.dll
2014-11-12 09:15 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\SysWow64\msi.dll
2014-11-09 19:51 . 2014-11-10 14:25 -------- d-----w- c:\users\7\AppData\Roaming\Quake3
2014-11-09 19:46 . 2014-11-09 19:48 -------- d-----w- c:\program files (x86)\ioQuake3&TA
2014-11-03 16:51 . 2014-06-16 06:01 206080 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2014-11-03 16:51 . 2014-06-16 06:01 110336 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2014-11-03 16:48 . 2014-11-03 16:48 -------- d-----w- c:\program files (x86)\MarkAny
2014-11-03 16:47 . 2014-11-03 16:47 -------- d-----w- c:\users\7\AppData\Local\Samsung
2014-11-03 16:47 . 2014-11-03 16:47 -------- d-----w- c:\users\7\AppData\Roaming\Samsung
2014-11-03 16:45 . 2014-04-30 18:43 144664 ----a-w- c:\windows\SysWow64\secman.dll
2014-11-03 16:45 . 2014-04-30 18:43 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2014-11-03 16:44 . 2014-11-03 16:46 -------- d-----w- c:\program files (x86)\Samsung
2014-11-03 16:44 . 2014-11-03 16:46 -------- d-----w- c:\programdata\Samsung
2014-11-03 16:42 . 2014-11-03 16:42 -------- d-----w- c:\users\7\AppData\Local\Downloaded Installations
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-25 21:49 . 2014-10-16 18:22 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-25 21:49 . 2014-10-16 18:22 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-11-12 00:19 . 2014-10-16 19:04 103374192 ----a-w- c:\windows\system32\MRT.exe
2014-11-04 13:30 . 2014-10-16 18:00 275080 ------w- c:\windows\system32\MpSigStub.exe
2014-10-26 21:43 . 2014-10-26 21:43 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-10-26 21:43 . 2014-10-26 21:43 226304 ----a-w- c:\windows\system32\elshyph.dll
2014-10-26 21:43 . 2014-10-26 21:43 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-10-26 21:43 . 2014-10-26 21:43 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2014-10-26 21:43 . 2014-10-26 21:43 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-10-26 21:43 . 2014-10-26 21:43 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-10-26 21:43 . 2014-10-26 21:43 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2014-10-26 21:43 . 2014-10-26 21:43 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-10-26 21:43 . 2014-10-26 21:43 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-10-26 21:43 . 2014-10-26 21:43 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2014-10-26 21:43 . 2014-10-26 21:43 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-10-26 21:43 . 2014-10-26 21:43 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-10-26 21:43 . 2014-10-26 21:43 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-10-26 21:43 . 2014-10-26 21:43 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-10-26 21:43 . 2014-10-26 21:43 361984 ----a-w- c:\windows\SysWow64\html.iec
2014-10-26 21:43 . 2014-10-26 21:43 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-10-26 21:43 . 2014-10-26 21:43 216064 ----a-w- c:\windows\system32\msls31.dll
2014-10-26 21:43 . 2014-10-26 21:43 441856 ----a-w- c:\windows\system32\html.iec
2014-10-26 21:43 . 2014-10-26 21:43 81408 ----a-w- c:\windows\system32\icardie.dll
2014-10-26 21:43 . 2014-10-26 21:43 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2014-10-26 21:43 . 2014-10-26 21:43 235008 ----a-w- c:\windows\system32\url.dll
2014-10-26 21:43 . 2014-10-26 21:43 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2014-10-26 21:43 . 2014-10-26 21:43 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-10-26 21:43 . 2014-10-26 21:43 247296 ----a-w- c:\windows\system32\webcheck.dll
2014-10-26 21:43 . 2014-10-26 21:43 27648 ----a-w- c:\windows\system32\licmgr10.dll
2014-10-26 21:43 . 2014-10-26 21:42 102912 ----a-w- c:\windows\system32\inseng.dll
2014-10-26 21:42 . 2014-10-26 21:42 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-10-26 21:42 . 2014-10-26 21:42 144896 ----a-w- c:\windows\system32\wextract.exe
2014-10-26 21:42 . 2014-10-26 21:42 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2014-10-26 21:42 . 2014-10-26 21:42 62976 ----a-w- c:\windows\system32\pngfilt.dll
2014-10-26 21:42 . 2014-10-26 21:42 149504 ----a-w- c:\windows\system32\occache.dll
2014-10-26 21:42 . 2014-10-26 21:42 13824 ----a-w- c:\windows\system32\mshta.exe
2014-10-26 21:42 . 2014-10-26 21:42 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-10-26 21:42 . 2014-10-26 21:42 51200 ----a-w- c:\windows\system32\imgutil.dll
2014-10-26 21:42 . 2014-10-26 21:42 136192 ----a-w- c:\windows\system32\iepeers.dll
2014-10-26 21:42 . 2014-10-26 21:42 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-10-26 21:42 . 2014-10-26 21:42 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2014-10-26 21:42 . 2014-10-26 21:42 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-10-26 21:42 . 2014-10-26 21:42 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-10-26 21:42 . 2014-10-26 21:42 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-10-26 19:39 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2014-10-26 19:39 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-10-17 19:45 . 2014-10-17 19:45 859648 ----a-w- c:\windows\system32\tdh.dll
2014-10-17 19:45 . 2014-10-17 19:45 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-10-17 19:45 . 2014-10-17 19:45 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-10-17 19:45 . 2014-10-17 19:45 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-10-17 19:45 . 2014-10-17 19:45 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-10-17 19:45 . 2014-10-17 19:45 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-10-17 19:44 . 2014-10-17 19:44 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-10-17 19:44 . 2014-10-17 19:44 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-10-17 19:33 . 2014-10-17 19:33 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2014-10-17 19:33 . 2014-10-17 19:33 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2014-10-17 19:33 . 2014-10-17 19:33 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2014-10-17 19:33 . 2014-10-17 19:33 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-10-17 19:33 . 2014-10-17 19:33 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-10-17 19:33 . 2014-10-17 19:33 363008 ----a-w- c:\windows\system32\dxgi.dll
2014-10-17 19:33 . 2014-10-17 19:33 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2014-10-17 19:33 . 2014-10-17 19:33 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2014-10-17 19:33 . 2014-10-17 19:33 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2014-10-17 19:33 . 2014-10-17 19:33 1175552 ----a-w- c:\windows\system32\FntCache.dll
2014-10-17 19:33 . 2014-10-17 19:33 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
2014-10-17 19:33 . 2014-10-17 19:33 1643520 ----a-w- c:\windows\system32\DWrite.dll
2014-10-17 19:33 . 2014-10-17 19:33 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-10-17 19:33 . 2014-10-17 19:33 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-10-17 19:33 . 2014-10-17 19:33 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-10-17 19:33 . 2014-10-17 19:33 296960 ----a-w- c:\windows\system32\d3d10core.dll
2014-10-17 19:33 . 2014-10-17 19:33 1238528 ----a-w- c:\windows\system32\d3d10.dll
2014-10-17 19:33 . 2014-10-17 19:33 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-10-17 19:33 . 2014-10-17 19:33 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-10-17 19:33 . 2014-10-17 19:33 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2014-10-17 19:33 . 2014-10-17 19:33 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-10-17 19:33 . 2014-10-17 19:33 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2014-10-17 19:33 . 2014-10-17 19:33 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2014-10-17 19:33 . 2014-10-17 19:33 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2014-10-17 19:29 . 2014-10-17 19:29 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-10-17 19:29 . 2014-10-17 19:29 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-10-16 18:45 . 2014-10-16 18:45 319456 ----a-w- c:\windows\DIFxAPI.dll
2014-09-25 02:08 . 2014-10-18 13:05 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-09-25 01:40 . 2014-10-18 13:05 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-09-15 767200]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-11-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-16 21:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2013-08-19 5617432]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mDefault_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1413487354&from=cvs&uid=126614527_331763_DC6589E3&q={searchTerms}
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1413487354&from=cvs&uid=126614527_331763_DC6589E3&q={searchTerms}
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 83.240.0.135 83.240.0.214
FF - ProfilePath - c:\users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default\
FF - prefs.js: browser.startup.homepage - www.centrum.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-11-29 11:30:02
ComboFix-quarantined-files.txt 2014-11-29 10:30
.
Před spuštěním: Volných bajtů: 76 635 041 792
Po spuštění: Volných bajtů: 76 217 544 704
.
- - End Of File - - B4D25810E68CBD1140691AE44243A8BE
A36C5E4F47E84449FF07ED3517B43A31
- Rudy
- Site Admin
- Příspěvky: 119556
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Zpomalené PC
Zdravím!
Spusťte nejprve tuto utilitu:
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://www.stahuj.centrum.cz/utility_a_ ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve >Scan< a potom na >Clean< (smazat)
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Zpomalené PC
# AdwCleaner v4.102 - Report created 29/11/2014 at 12:55:33
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : 7 - 7-PC
# Running from : C:\Users\7\Desktop\adwcleaner_4.102.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\Users\7\AppData\Local\CrashRpt
Folder Deleted : C:\Users\7\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\7\AppData\Roaming\ParetoLogic
File Deleted : C:\Windows\System32\log\iSafeKrnlCall.log
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKLM\SOFTWARE\ParetoLogic
Key Deleted : HKLM\SOFTWARE\Solvusoft
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.17148
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v33.1 (x86 cs)
*************************
AdwCleaner[R0].txt - [2534 octets] - [29/11/2014 12:53:25]
AdwCleaner[S0].txt - [2175 octets] - [29/11/2014 12:55:33]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2235 octets] ##########
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : 7 - 7-PC
# Running from : C:\Users\7\Desktop\adwcleaner_4.102.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\Users\7\AppData\Local\CrashRpt
Folder Deleted : C:\Users\7\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\7\AppData\Roaming\ParetoLogic
File Deleted : C:\Windows\System32\log\iSafeKrnlCall.log
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKLM\SOFTWARE\ParetoLogic
Key Deleted : HKLM\SOFTWARE\Solvusoft
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.17148
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v33.1 (x86 cs)
*************************
AdwCleaner[R0].txt - [2534 octets] - [29/11/2014 12:53:25]
AdwCleaner[S0].txt - [2175 octets] - [29/11/2014 12:55:33]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2235 octets] ##########
- Rudy
- Site Admin
- Příspěvky: 119556
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Zpomalené PC
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Zpomalené PC
Logfile of random's system information tool 1.10 (written by random/random)
Run by 7 at 2014-11-29 13:01:40
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 73 GB (48%) free of 153 GB
Total RAM: 2047 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:01:45, on 29.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.17148)
Boot mode: Normal
Running processes:
C:\Users\7\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\7.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 4582 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.239 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-09-15 767200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-11-29 12:52:50 ----D---- C:\AdwCleaner
2014-11-29 11:40:14 ----D---- C:\rsit
2014-11-29 11:40:14 ----D---- C:\Program Files (x86)\trend micro
2014-11-29 11:30:12 ----SHD---- C:\$RECYCLE.BIN
2014-11-29 11:30:05 ----D---- C:\Windows\temp
2014-11-29 11:30:03 ----A---- C:\ComboFix.txt
2014-11-29 11:16:18 ----A---- C:\Windows\zip.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWSC.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWREG.exe
2014-11-29 11:16:18 ----A---- C:\Windows\sed.exe
2014-11-29 11:16:18 ----A---- C:\Windows\PEV.exe
2014-11-29 11:16:18 ----A---- C:\Windows\NIRCMD.exe
2014-11-29 11:16:18 ----A---- C:\Windows\MBR.exe
2014-11-29 11:16:18 ----A---- C:\Windows\grep.exe
2014-11-29 11:15:38 ----D---- C:\Qoobox
2014-11-29 11:15:03 ----D---- C:\Windows\erdnt
2014-11-23 00:27:29 ----D---- C:\ProgramData\ATI
2014-11-23 00:24:23 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:12:19 ----D---- C:\Program Files (x86)\Common Files\Skype
2014-11-18 21:12:18 ----RD---- C:\Program Files (x86)\Skype
2014-11-12 16:49:39 ----D---- C:\Users\7\AppData\Roaming\fltk.org
2014-11-12 16:49:14 ----D---- C:\Users\7\AppData\Roaming\flightgear.org
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\msaudite.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\adtschema.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\schannel.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\wdigest.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\credssp.dll
2014-11-12 11:22:12 ----A---- C:\Windows\SysWOW64\packager.dll
2014-11-12 10:15:19 ----A---- C:\Windows\SysWOW64\msi.dll
2014-11-12 10:14:41 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 10:14:39 ----A---- C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 10:14:36 ----A---- C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3.dll
2014-11-12 10:14:20 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-11-12 10:14:16 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-11-12 10:14:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2014-11-12 10:14:09 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-11-11 11:17:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-09 20:51:05 ----D---- C:\Users\7\AppData\Roaming\Quake3
2014-11-09 20:46:07 ----D---- C:\Program Files (x86)\ioQuake3&TA
2014-11-03 17:48:32 ----D---- C:\Program Files (x86)\MarkAny
2014-11-03 17:47:35 ----D---- C:\Users\7\AppData\Roaming\Samsung
2014-11-03 17:45:56 ----A---- C:\Windows\SysWOW64\secman.dll
2014-11-03 17:45:50 ----A---- C:\Windows\SysWOW64\Redemption.dll
2014-11-03 17:44:05 ----D---- C:\ProgramData\Samsung
2014-11-03 17:44:05 ----D---- C:\Program Files (x86)\Samsung
======List of files/folders modified in the last 1 month======
2014-11-29 13:01:36 ----D---- C:\Users\7\AppData\Roaming\Skype
2014-11-29 12:56:43 ----D---- C:\Windows
2014-11-29 12:55:33 ----D---- C:\ProgramData
2014-11-29 11:40:14 ----RD---- C:\Program Files (x86)
2014-11-29 11:26:39 ----A---- C:\Windows\system.ini
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64\drivers
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64
2014-11-29 11:23:13 ----D---- C:\Windows\AppPatch
2014-11-29 11:23:11 ----D---- C:\Program Files (x86)\Common Files
2014-11-29 11:16:53 ----SHD---- C:\System Volume Information
2014-11-29 11:16:23 ----D---- C:\Windows\Prefetch
2014-11-28 14:14:34 ----D---- C:\Windows\inf
2014-11-25 22:49:12 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:28:35 ----D---- C:\Users\7\AppData\Roaming\uTorrent
2014-11-23 16:22:42 ----SD---- C:\Users\7\AppData\Roaming\Microsoft
2014-11-23 16:22:41 ----D---- C:\ProgramData\Microsoft Help
2014-11-23 10:43:10 ----D---- C:\Windows\Microsoft.NET
2014-11-23 00:46:21 ----D---- C:\Windows\winsxs
2014-11-23 00:36:18 ----SHD---- C:\Windows\Installer
2014-11-23 00:36:17 ----D---- C:\Config.Msi
2014-11-23 00:35:07 ----D---- C:\Windows\System32
2014-11-23 00:33:33 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2014-11-23 00:29:49 ----D---- C:\ProgramData\AMD
2014-11-18 21:12:16 ----D---- C:\ProgramData\Skype
2014-11-18 16:11:12 ----D---- C:\Windows\Panther
2014-11-18 16:11:12 ----D---- C:\Windows\debug
2014-11-12 17:08:22 ----RD---- C:\Program Files
2014-11-12 12:54:07 ----D---- C:\Windows\rescache
2014-11-12 12:00:28 ----RSD---- C:\Windows\assembly
2014-11-12 11:49:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-11-12 11:11:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-08 11:04:26 ----SD---- C:\ProgramData\Microsoft
2014-11-06 20:19:12 ----D---- C:\Windows\Tasks
2014-11-03 17:45:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys []
S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 344064]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2013-08-19 1337240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-25 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetPipeActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetTcpActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
-----------------EOF-----------------
Run by 7 at 2014-11-29 13:01:40
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 73 GB (48%) free of 153 GB
Total RAM: 2047 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:01:45, on 29.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.17148)
Boot mode: Normal
Running processes:
C:\Users\7\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\7.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 4582 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.239 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-09-15 767200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-11-29 12:52:50 ----D---- C:\AdwCleaner
2014-11-29 11:40:14 ----D---- C:\rsit
2014-11-29 11:40:14 ----D---- C:\Program Files (x86)\trend micro
2014-11-29 11:30:12 ----SHD---- C:\$RECYCLE.BIN
2014-11-29 11:30:05 ----D---- C:\Windows\temp
2014-11-29 11:30:03 ----A---- C:\ComboFix.txt
2014-11-29 11:16:18 ----A---- C:\Windows\zip.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWSC.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWREG.exe
2014-11-29 11:16:18 ----A---- C:\Windows\sed.exe
2014-11-29 11:16:18 ----A---- C:\Windows\PEV.exe
2014-11-29 11:16:18 ----A---- C:\Windows\NIRCMD.exe
2014-11-29 11:16:18 ----A---- C:\Windows\MBR.exe
2014-11-29 11:16:18 ----A---- C:\Windows\grep.exe
2014-11-29 11:15:38 ----D---- C:\Qoobox
2014-11-29 11:15:03 ----D---- C:\Windows\erdnt
2014-11-23 00:27:29 ----D---- C:\ProgramData\ATI
2014-11-23 00:24:23 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:12:19 ----D---- C:\Program Files (x86)\Common Files\Skype
2014-11-18 21:12:18 ----RD---- C:\Program Files (x86)\Skype
2014-11-12 16:49:39 ----D---- C:\Users\7\AppData\Roaming\fltk.org
2014-11-12 16:49:14 ----D---- C:\Users\7\AppData\Roaming\flightgear.org
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\msaudite.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\adtschema.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\schannel.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\wdigest.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\credssp.dll
2014-11-12 11:22:12 ----A---- C:\Windows\SysWOW64\packager.dll
2014-11-12 10:15:19 ----A---- C:\Windows\SysWOW64\msi.dll
2014-11-12 10:14:41 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 10:14:39 ----A---- C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 10:14:36 ----A---- C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3.dll
2014-11-12 10:14:20 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-11-12 10:14:16 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-11-12 10:14:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2014-11-12 10:14:09 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-11-11 11:17:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-09 20:51:05 ----D---- C:\Users\7\AppData\Roaming\Quake3
2014-11-09 20:46:07 ----D---- C:\Program Files (x86)\ioQuake3&TA
2014-11-03 17:48:32 ----D---- C:\Program Files (x86)\MarkAny
2014-11-03 17:47:35 ----D---- C:\Users\7\AppData\Roaming\Samsung
2014-11-03 17:45:56 ----A---- C:\Windows\SysWOW64\secman.dll
2014-11-03 17:45:50 ----A---- C:\Windows\SysWOW64\Redemption.dll
2014-11-03 17:44:05 ----D---- C:\ProgramData\Samsung
2014-11-03 17:44:05 ----D---- C:\Program Files (x86)\Samsung
======List of files/folders modified in the last 1 month======
2014-11-29 13:01:36 ----D---- C:\Users\7\AppData\Roaming\Skype
2014-11-29 12:56:43 ----D---- C:\Windows
2014-11-29 12:55:33 ----D---- C:\ProgramData
2014-11-29 11:40:14 ----RD---- C:\Program Files (x86)
2014-11-29 11:26:39 ----A---- C:\Windows\system.ini
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64\drivers
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64
2014-11-29 11:23:13 ----D---- C:\Windows\AppPatch
2014-11-29 11:23:11 ----D---- C:\Program Files (x86)\Common Files
2014-11-29 11:16:53 ----SHD---- C:\System Volume Information
2014-11-29 11:16:23 ----D---- C:\Windows\Prefetch
2014-11-28 14:14:34 ----D---- C:\Windows\inf
2014-11-25 22:49:12 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:28:35 ----D---- C:\Users\7\AppData\Roaming\uTorrent
2014-11-23 16:22:42 ----SD---- C:\Users\7\AppData\Roaming\Microsoft
2014-11-23 16:22:41 ----D---- C:\ProgramData\Microsoft Help
2014-11-23 10:43:10 ----D---- C:\Windows\Microsoft.NET
2014-11-23 00:46:21 ----D---- C:\Windows\winsxs
2014-11-23 00:36:18 ----SHD---- C:\Windows\Installer
2014-11-23 00:36:17 ----D---- C:\Config.Msi
2014-11-23 00:35:07 ----D---- C:\Windows\System32
2014-11-23 00:33:33 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2014-11-23 00:29:49 ----D---- C:\ProgramData\AMD
2014-11-18 21:12:16 ----D---- C:\ProgramData\Skype
2014-11-18 16:11:12 ----D---- C:\Windows\Panther
2014-11-18 16:11:12 ----D---- C:\Windows\debug
2014-11-12 17:08:22 ----RD---- C:\Program Files
2014-11-12 12:54:07 ----D---- C:\Windows\rescache
2014-11-12 12:00:28 ----RSD---- C:\Windows\assembly
2014-11-12 11:49:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-11-12 11:11:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-08 11:04:26 ----SD---- C:\ProgramData\Microsoft
2014-11-06 20:19:12 ----D---- C:\Windows\Tasks
2014-11-03 17:45:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys []
S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 344064]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2013-08-19 1337240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-25 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetPipeActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetTcpActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119556
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Zpomalené PC
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
Proč spouštíte ComboFix, utilitu určenou profesionálům? Hodláte si nabourat systém, nebo některou aplikaci?
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.:reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Proč spouštíte ComboFix, utilitu určenou profesionálům? Hodláte si nabourat systém, nebo některou aplikaci?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Zpomalené PC
Logfile of random's system information tool 1.10 (written by random/random)
Run by 7 at 2014-11-29 14:25:15
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 73 GB (48%) free of 153 GB
Total RAM: 2047 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:25:18, on 29.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.17148)
Boot mode: Normal
Running processes:
C:\Users\7\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\7.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\RunOnce: [OTM] "C:\Users\7\Desktop\OTM.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 4640 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.239 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-09-15 767200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"OTM"=C:\Users\7\Desktop\OTM.exe [2014-11-29 522240]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-11-29 14:18:16 ----D---- C:\_OTM
2014-11-29 12:52:50 ----D---- C:\AdwCleaner
2014-11-29 11:40:14 ----D---- C:\rsit
2014-11-29 11:40:14 ----D---- C:\Program Files (x86)\trend micro
2014-11-29 11:30:12 ----SHD---- C:\$RECYCLE.BIN
2014-11-29 11:30:05 ----D---- C:\Windows\temp
2014-11-29 11:30:03 ----A---- C:\ComboFix.txt
2014-11-29 11:16:18 ----A---- C:\Windows\zip.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWSC.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWREG.exe
2014-11-29 11:16:18 ----A---- C:\Windows\sed.exe
2014-11-29 11:16:18 ----A---- C:\Windows\PEV.exe
2014-11-29 11:16:18 ----A---- C:\Windows\NIRCMD.exe
2014-11-29 11:16:18 ----A---- C:\Windows\MBR.exe
2014-11-29 11:16:18 ----A---- C:\Windows\grep.exe
2014-11-29 11:15:38 ----D---- C:\Qoobox
2014-11-29 11:15:03 ----D---- C:\Windows\erdnt
2014-11-23 00:27:29 ----D---- C:\ProgramData\ATI
2014-11-23 00:24:23 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:12:19 ----D---- C:\Program Files (x86)\Common Files\Skype
2014-11-18 21:12:18 ----RD---- C:\Program Files (x86)\Skype
2014-11-12 16:49:39 ----D---- C:\Users\7\AppData\Roaming\fltk.org
2014-11-12 16:49:14 ----D---- C:\Users\7\AppData\Roaming\flightgear.org
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\msaudite.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\adtschema.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\schannel.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\wdigest.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\credssp.dll
2014-11-12 11:22:12 ----A---- C:\Windows\SysWOW64\packager.dll
2014-11-12 10:15:19 ----A---- C:\Windows\SysWOW64\msi.dll
2014-11-12 10:14:41 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 10:14:39 ----A---- C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 10:14:36 ----A---- C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3.dll
2014-11-12 10:14:20 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-11-12 10:14:16 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-11-12 10:14:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2014-11-12 10:14:09 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-11-11 11:17:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-09 20:51:05 ----D---- C:\Users\7\AppData\Roaming\Quake3
2014-11-09 20:46:07 ----D---- C:\Program Files (x86)\ioQuake3&TA
2014-11-03 17:48:32 ----D---- C:\Program Files (x86)\MarkAny
2014-11-03 17:47:35 ----D---- C:\Users\7\AppData\Roaming\Samsung
2014-11-03 17:45:56 ----A---- C:\Windows\SysWOW64\secman.dll
2014-11-03 17:45:50 ----A---- C:\Windows\SysWOW64\Redemption.dll
2014-11-03 17:44:05 ----D---- C:\ProgramData\Samsung
2014-11-03 17:44:05 ----D---- C:\Program Files (x86)\Samsung
======List of files/folders modified in the last 1 month======
2014-11-29 14:18:59 ----D---- C:\Windows
2014-11-29 14:16:52 ----D---- C:\Users\7\AppData\Roaming\Skype
2014-11-29 12:55:33 ----D---- C:\ProgramData
2014-11-29 11:40:14 ----RD---- C:\Program Files (x86)
2014-11-29 11:26:39 ----A---- C:\Windows\system.ini
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64\drivers
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64
2014-11-29 11:23:13 ----D---- C:\Windows\AppPatch
2014-11-29 11:23:11 ----D---- C:\Program Files (x86)\Common Files
2014-11-29 11:16:53 ----SHD---- C:\System Volume Information
2014-11-29 11:16:23 ----D---- C:\Windows\Prefetch
2014-11-28 14:14:34 ----D---- C:\Windows\inf
2014-11-25 22:49:12 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:28:35 ----D---- C:\Users\7\AppData\Roaming\uTorrent
2014-11-23 16:22:42 ----SD---- C:\Users\7\AppData\Roaming\Microsoft
2014-11-23 16:22:41 ----D---- C:\ProgramData\Microsoft Help
2014-11-23 10:43:10 ----D---- C:\Windows\Microsoft.NET
2014-11-23 00:46:21 ----D---- C:\Windows\winsxs
2014-11-23 00:36:18 ----SHD---- C:\Windows\Installer
2014-11-23 00:36:17 ----D---- C:\Config.Msi
2014-11-23 00:35:07 ----D---- C:\Windows\System32
2014-11-23 00:33:33 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2014-11-23 00:29:49 ----D---- C:\ProgramData\AMD
2014-11-18 21:12:16 ----D---- C:\ProgramData\Skype
2014-11-18 16:11:12 ----D---- C:\Windows\Panther
2014-11-18 16:11:12 ----D---- C:\Windows\debug
2014-11-12 17:08:22 ----RD---- C:\Program Files
2014-11-12 12:54:07 ----D---- C:\Windows\rescache
2014-11-12 12:00:28 ----RSD---- C:\Windows\assembly
2014-11-12 11:49:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-11-12 11:11:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-08 11:04:26 ----SD---- C:\ProgramData\Microsoft
2014-11-06 20:19:12 ----D---- C:\Windows\Tasks
2014-11-03 17:45:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys []
S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 344064]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2013-08-19 1337240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-25 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetPipeActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetTcpActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
-----------------EOF-----------------
Run by 7 at 2014-11-29 14:25:15
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 73 GB (48%) free of 153 GB
Total RAM: 2047 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:25:18, on 29.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.17148)
Boot mode: Normal
Running processes:
C:\Users\7\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\7.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\RunOnce: [OTM] "C:\Users\7\Desktop\OTM.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 4640 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\7\AppData\Roaming\Mozilla\Firefox\Profiles\mace5czf.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.239 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-09-15 767200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"OTM"=C:\Users\7\Desktop\OTM.exe [2014-11-29 522240]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-11-29 14:18:16 ----D---- C:\_OTM
2014-11-29 12:52:50 ----D---- C:\AdwCleaner
2014-11-29 11:40:14 ----D---- C:\rsit
2014-11-29 11:40:14 ----D---- C:\Program Files (x86)\trend micro
2014-11-29 11:30:12 ----SHD---- C:\$RECYCLE.BIN
2014-11-29 11:30:05 ----D---- C:\Windows\temp
2014-11-29 11:30:03 ----A---- C:\ComboFix.txt
2014-11-29 11:16:18 ----A---- C:\Windows\zip.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWSC.exe
2014-11-29 11:16:18 ----A---- C:\Windows\SWREG.exe
2014-11-29 11:16:18 ----A---- C:\Windows\sed.exe
2014-11-29 11:16:18 ----A---- C:\Windows\PEV.exe
2014-11-29 11:16:18 ----A---- C:\Windows\NIRCMD.exe
2014-11-29 11:16:18 ----A---- C:\Windows\MBR.exe
2014-11-29 11:16:18 ----A---- C:\Windows\grep.exe
2014-11-29 11:15:38 ----D---- C:\Qoobox
2014-11-29 11:15:03 ----D---- C:\Windows\erdnt
2014-11-23 00:27:29 ----D---- C:\ProgramData\ATI
2014-11-23 00:24:23 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:57:06 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:12:19 ----D---- C:\Program Files (x86)\Common Files\Skype
2014-11-18 21:12:18 ----RD---- C:\Program Files (x86)\Skype
2014-11-12 16:49:39 ----D---- C:\Users\7\AppData\Roaming\fltk.org
2014-11-12 16:49:14 ----D---- C:\Users\7\AppData\Roaming\flightgear.org
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\msaudite.dll
2014-11-12 11:23:17 ----A---- C:\Windows\SysWOW64\adtschema.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\schannel.dll
2014-11-12 11:23:08 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\wdigest.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 11:23:07 ----A---- C:\Windows\SysWOW64\credssp.dll
2014-11-12 11:22:12 ----A---- C:\Windows\SysWOW64\packager.dll
2014-11-12 10:15:19 ----A---- C:\Windows\SysWOW64\msi.dll
2014-11-12 10:14:41 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 10:14:39 ----A---- C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 10:14:38 ----A---- C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 10:14:36 ----A---- C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 10:14:33 ----A---- C:\Windows\SysWOW64\msxml3.dll
2014-11-12 10:14:20 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-11-12 10:14:16 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-11-12 10:14:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-11-12 10:14:13 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2014-11-12 10:14:11 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-11-12 10:14:10 ----A---- C:\Windows\SysWOW64\jscript.dll
2014-11-12 10:14:09 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 10:14:08 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-12 10:14:07 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-11-11 11:17:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-09 20:51:05 ----D---- C:\Users\7\AppData\Roaming\Quake3
2014-11-09 20:46:07 ----D---- C:\Program Files (x86)\ioQuake3&TA
2014-11-03 17:48:32 ----D---- C:\Program Files (x86)\MarkAny
2014-11-03 17:47:35 ----D---- C:\Users\7\AppData\Roaming\Samsung
2014-11-03 17:45:56 ----A---- C:\Windows\SysWOW64\secman.dll
2014-11-03 17:45:50 ----A---- C:\Windows\SysWOW64\Redemption.dll
2014-11-03 17:44:05 ----D---- C:\ProgramData\Samsung
2014-11-03 17:44:05 ----D---- C:\Program Files (x86)\Samsung
======List of files/folders modified in the last 1 month======
2014-11-29 14:18:59 ----D---- C:\Windows
2014-11-29 14:16:52 ----D---- C:\Users\7\AppData\Roaming\Skype
2014-11-29 12:55:33 ----D---- C:\ProgramData
2014-11-29 11:40:14 ----RD---- C:\Program Files (x86)
2014-11-29 11:26:39 ----A---- C:\Windows\system.ini
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64\drivers
2014-11-29 11:23:13 ----D---- C:\Windows\SysWOW64
2014-11-29 11:23:13 ----D---- C:\Windows\AppPatch
2014-11-29 11:23:11 ----D---- C:\Program Files (x86)\Common Files
2014-11-29 11:16:53 ----SHD---- C:\System Volume Information
2014-11-29 11:16:23 ----D---- C:\Windows\Prefetch
2014-11-28 14:14:34 ----D---- C:\Windows\inf
2014-11-25 22:49:12 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:28:35 ----D---- C:\Users\7\AppData\Roaming\uTorrent
2014-11-23 16:22:42 ----SD---- C:\Users\7\AppData\Roaming\Microsoft
2014-11-23 16:22:41 ----D---- C:\ProgramData\Microsoft Help
2014-11-23 10:43:10 ----D---- C:\Windows\Microsoft.NET
2014-11-23 00:46:21 ----D---- C:\Windows\winsxs
2014-11-23 00:36:18 ----SHD---- C:\Windows\Installer
2014-11-23 00:36:17 ----D---- C:\Config.Msi
2014-11-23 00:35:07 ----D---- C:\Windows\System32
2014-11-23 00:33:33 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2014-11-23 00:29:49 ----D---- C:\ProgramData\AMD
2014-11-18 21:12:16 ----D---- C:\ProgramData\Skype
2014-11-18 16:11:12 ----D---- C:\Windows\Panther
2014-11-18 16:11:12 ----D---- C:\Windows\debug
2014-11-12 17:08:22 ----RD---- C:\Program Files
2014-11-12 12:54:07 ----D---- C:\Windows\rescache
2014-11-12 12:00:28 ----RSD---- C:\Windows\assembly
2014-11-12 11:49:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-11-12 11:11:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-08 11:04:26 ----SD---- C:\ProgramData\Microsoft
2014-11-06 20:19:12 ----D---- C:\Windows\Tasks
2014-11-03 17:45:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys []
S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 344064]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2013-08-19 1337240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-25 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetPipeActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
S4 NetTcpActivator;@%SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2014-07-10 117392]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119556
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Zpomalené PC
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Zpomalené PC
Ano zda se že je vše rychlejší. Můžete stručně popsat v čem byl problém, případně kde jsem mohl nějakého vira chytnul??
Děkuji
Děkuji
- Rudy
- Site Admin
- Příspěvky: 119556
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Zpomalené PC
Přímo vir to nebyl. Měl jste pár AdWarů a zbytečnosti. Nemáte zač! 

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.