ComboFix 10-11-22.01 - Mára 22.11.2010 19:37:30.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2814.1804 [GMT 1:00]
Spuštěný z: c:\users\Mára\Documents\Downloads\Programs\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *enabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\common.data
c:\recycler\S-1-5-21-2023866187-2730677406-710175143-0465\yv8g67.exe
c:\users\Mára\AppData\Roaming\Microsoft\cyso.exe
c:\users\Mára\AppData\Roaming\Microsoft\looquu.exe
c:\users\Mára\AppData\Roaming\Microsoft\pujoo.exe
c:\windows\system32\secupdat.dat
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-10-22 do 2010-11-22 )))))))))))))))))))))))))))))))
.
2010-11-22 18:42 . 2010-11-22 18:44 -------- d-----w- c:\users\Mára\AppData\Local\temp
2010-11-22 18:42 . 2010-11-22 18:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pp6aavk4fvv.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pkf9a0vq0k0.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\kaav1qkkfv.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\v5pffaqq.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\kvpkkakvkk.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fpk0pf1v.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\6vk5faf.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0vapkpk.exe
2010-11-22 17:24 . 2010-11-22 17:24 18432 ---ha-w- c:\users\Mára\ipuupt.exe
2010-11-22 17:19 . 2010-11-22 17:19 18432 ---ha-w- c:\users\Mára\hdgqvm.exe
2010-11-22 16:17 . 2010-11-22 16:17 -------- d-----w- C:\_OTM
2010-11-22 13:14 . 2010-11-22 13:24 -------- d-----w- c:\users\Mára\AppData\Roaming\IDM
2010-11-22 13:07 . 2010-11-22 13:14 -------- d-----w- c:\program files\Internet download manager
2010-11-22 12:25 . 2010-11-22 12:31 -------- d-----w- c:\program files\trend micro
2010-11-22 12:25 . 2010-11-22 12:31 -------- d-----w- C:\rsit
2010-11-20 22:53 . 2010-11-20 22:53 85504 --sh--r- c:\users\Mára\AppData\Roaming\juzjf.exe
2010-11-19 08:24 . 2010-11-22 17:58 -------- d-----w- c:\users\Mára\AppData\Roaming\OpenOffice.org2
2010-11-19 08:23 . 2010-11-19 08:23 -------- d-----w- c:\program files\OpenOffice.org 2.3
2010-11-18 16:32 . 2010-11-22 16:30 -------- d-----w- c:\users\Mára\AppData\Roaming\skypePM
2010-11-18 16:29 . 2010-11-18 16:29 -------- d-----w- c:\program files\Common Files\Skype
2010-11-18 16:29 . 2010-11-18 16:29 -------- d-----r- c:\program files\Skype
2010-11-18 16:29 . 2010-11-22 17:58 -------- d-----w- c:\users\Mára\AppData\Roaming\Skype
2010-11-18 16:29 . 2010-11-18 16:29 -------- d-----w- c:\programdata\Skype
2010-11-18 06:50 . 2010-11-18 16:08 -------- d-----w- c:\program files\Metinn2
2010-11-17 21:23 . 2010-11-18 06:50 -------- d-----w- c:\program files\Metin2
2010-11-16 18:18 . 2010-11-16 18:18 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2010-11-14 18:58 . 2010-11-15 18:58 -------- d-----w- c:\users\Mára\AppData\Local\LogMeIn Hamachi
2010-11-14 18:35 . 2010-11-14 18:57 -------- d-----w- c:\users\Mára\AppData\Roaming\Hamachi
2010-11-14 18:03 . 2010-11-22 13:20 -------- d-----w- c:\program files\Vietcong
2010-11-09 13:31 . 2010-11-09 13:31 -------- d-----w- c:\program files\Common Files\SourceTec
2010-11-08 16:25 . 2010-11-08 16:25 -------- d-----w- c:\windows\system32\RTCOM
2010-11-08 16:22 . 2010-11-08 16:22 -------- d-----w- c:\users\Mára\AppData\Local\Power2Go
2010-11-08 14:54 . 2010-11-08 14:54 -------- d-----w- c:\users\Mára\AppData\Roaming\CyberLink
2010-11-08 14:44 . 2007-01-08 21:17 27168 ------w- c:\windows\system32\msxml3a.dll
2010-11-08 14:38 . 2010-11-08 14:38 -------- d-----w- C:\MyWorks
2010-11-08 14:37 . 2007-03-22 20:28 1053232 ------w- c:\windows\system32\MFC71u.dll
2010-11-08 14:37 . 2007-03-22 20:28 1066544 ------w- c:\windows\system32\MFC71.dll
2010-11-08 14:37 . 2007-03-22 20:27 505392 ------w- c:\windows\system32\msvcp71.dll
2010-11-08 14:37 . 2010-11-08 14:46 -------- d-----w- c:\program files\CyberLink
2010-11-08 14:37 . 2010-11-08 14:54 -------- d-----w- c:\programdata\CyberLink
2010-11-07 19:50 . 2010-11-02 18:28 3633256 ----a-w- c:\windows\system32\RtkAPO.dll
2010-11-07 19:44 . 2004-01-11 22:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-11-04 09:59 . 2000-08-19 18:29 268048 ----a-w- c:\windows\system32\dxtmeta2.dll
2010-11-03 12:38 . 2010-11-03 12:38 -------- d-----w- c:\users\Mára\AppData\Roaming\Leadertech
2010-11-03 12:12 . 2010-11-03 12:12 -------- d-----w- c:\program files\EA Sports
2010-11-03 11:10 . 2010-11-03 11:10 -------- d-----w- c:\users\Mára\AppData\Roaming\Unigraphics Solutions
2010-11-03 09:46 . 2010-11-03 09:46 -------- d-----w- c:\users\Mára\AppData\Local\4A Games
2010-11-03 08:56 . 2010-11-03 08:56 -------- d-----w- c:\users\Mára\AppData\Local\ESET
2010-11-03 08:54 . 2010-11-03 08:54 -------- d-----w- c:\program files\THQ
2010-11-03 08:03 . 2010-11-03 11:10 -------- d-----w- c:\program files\Solid Edge V20
2010-11-02 15:46 . 2010-11-02 15:46 -------- d-----w- c:\users\Mára\AppData\Local\FEMAP
2010-11-02 15:41 . 2007-06-29 13:47 34304 ----a-w- c:\windows\system32\drivers\AmdLLD.sys
2010-11-02 15:40 . 2010-11-02 15:40 -------- d-----w- c:\users\Mára\AppData\Local\Downloaded Installations
2010-10-31 12:25 . 2010-10-31 12:25 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2010-10-31 12:25 . 2010-10-31 12:25 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-10-29 22:16 . 2010-10-29 22:16 -------- d-----w- c:\programdata\KONAMI
2010-10-29 21:32 . 2010-10-29 22:16 -------- d-----w- c:\program files\KONAMI
2010-10-27 22:13 . 2010-10-27 22:13 -------- d-----w- c:\users\Mára\AppData\Roaming\Media Player Classic
2010-10-27 22:11 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2010-10-27 18:42 . 2010-11-22 13:16 -------- d-----w- c:\users\Mára\AppData\Roaming\DMCache
2010-10-27 18:35 . 2010-10-27 18:35 -------- d-----w- c:\users\Mára\AppData\Local\Stardock
2010-10-27 18:34 . 2010-10-27 18:34 -------- d-----w- c:\program files\Stardock
2010-10-27 18:34 . 2010-10-27 18:34 -------- d-----w- c:\program files\Common Files\Stardock
2010-10-24 18:45 . 2010-10-24 18:45 -------- d-----w- c:\users\Mára\AppData\Roaming\Ubisoft
2010-10-24 18:45 . 2010-10-24 18:45 -------- d-----w- c:\programdata\Ubisoft
2010-10-24 18:27 . 2010-10-24 18:27 -------- d-----w- c:\users\Mára\AppData\Roaming\QipGuard
2010-10-24 18:26 . 2010-10-24 18:27 -------- d-----w- c:\program files\QIP
2010-10-24 18:23 . 2010-10-24 18:23 -------- d-----w- c:\users\Mára\AppData\Roaming\QIP
2010-10-24 18:22 . 2010-10-24 18:24 -------- d-----w- c:\program files\QIP 2010
2010-10-24 17:33 . 2010-10-24 17:46 -------- d-----w- c:\program files\Ubisoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pp6aavk4fvv.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pp6aavk4fvv.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pkf9a0vq0k0.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pkf9a0vq0k0.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\kaav1qkkfv.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\kaav1qkkfv.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\v5pffaqq.exe
2010-11-22 17:58 . 2010-11-22 17:58 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\v5pffaqq.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fpk0pf1v.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fpk0pf1v.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\6vk5faf.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\6vk5faf.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\kvpkkakvkk.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\kvpkkakvkk.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0vapkpk.exe
2010-11-22 17:45 . 2010-11-22 17:45 43008 --sh--r- c:\users\Mára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0vapkpk.exe
2010-11-22 17:24 . 2010-11-22 17:24 18432 ---ha-w- c:\users\Mára\ipuupt.exe
2010-11-22 17:24 . 2010-11-22 17:24 18432 ---ha-w- c:\users\Mára\ipuupt.exe
2010-11-22 17:19 . 2010-11-22 17:19 18432 ---ha-w- c:\users\Mára\hdgqvm.exe
2010-11-22 17:19 . 2010-11-22 17:19 18432 ---ha-w- c:\users\Mára\hdgqvm.exe
2010-11-20 22:53 . 2010-11-20 22:53 85504 --sh--r- c:\users\Mára\AppData\Roaming\juzjf.exe
2010-11-20 22:53 . 2010-11-20 22:53 85504 --sh--r- c:\users\Mára\AppData\Roaming\juzjf.exe
2010-10-18 07:41 . 2010-10-09 17:29 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BDA22860-8B97-4DB2-915A-96E4E69A046A}\mpengine.dll
2010-10-10 14:38 . 2010-10-10 14:38 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-09 16:38 . 2010-10-09 16:38 520192 ----a-w- c:\windows\system32\K_Series_ScreenSaver_EN.scr
2010-10-09 16:38 . 2010-10-09 16:38 3054136 ----a-w- c:\windows\AsScrPro.exe
2010-10-09 16:36 . 2010-10-09 16:36 30264 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2009-04-08 08:31 . 2009-04-08 08:31 106496 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2008-08-11 19:45 . 2008-08-11 19:45 155648 ----a-w- c:\program files\Common Files\MSIactionall.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"QIP Internet Guardian"="c:\users\Mára\AppData\Roaming\QipGuard\QipGuard.exe" [2010-04-12 181760]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-05-26 3220912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-30 102400]
"ATKOSD2"="c:\program files\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"ATKMEDIA"="c:\program files\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-01-05 170624]
"HControlUser"="c:\program files\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
c:\users\M ra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
0vapkpk.exe [2010-11-22 43008]
6vk5faf.exe [2010-11-22 43008]
fpk0pf1v.exe [2010-11-22 43008]
kaav1qkkfv.exe [2010-11-22 43008]
kvpkkakvkk.exe [2010-11-22 43008]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-11-14 393216]
pkf9a0vq0k0.exe [2010-11-22 43008]
pp6aavk4fvv.exe [2010-11-22 43008]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-10-27 3444008]
v5pffaqq.exe [2010-11-22 43008]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 795936]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2010-10-9 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut4_E9C83B3EDF9141A39DA5EC05C79BBB91.exe [2010-10-9 156952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ASUS\ASUS Data Security Manager\ASPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
2009-06-24 10:30 272952 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ADSMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2010-10-09 16:38 3054136 ----a-w- c:\windows\AsScrPro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2010-11-02 18:28 9808488 ------w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe
R2 eoayaeexee7;Crystal Report Application Server;c:\users\Mára\AppData\Roaming\Microsoft\mejoujoo.exe [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 nccfbwpe;nccfbwpe;c:\windows\System32\Drivers\nccfbwpe.sys [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15416]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-10 691696]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2009-12-07 303744]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-30 172032]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-03-30 5429248]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-30 157184]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-07-01 43944]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-01-18 102400]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-08-18 119408]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver;c:\windows\system32\DRIVERS\JME.sys [2010-02-25 98928]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 30392]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with IDM - c:\program files\Internet download manager\IEExt.htm
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Stáhnout s IDM - c:\program files\Internet download manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files\Internet download manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files\Internet download manager\IEGetAll.htm
FF - ProfilePath - c:\users\Mára\AppData\Roaming\Mozilla\Firefox\Profiles\we31b8nu.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: c:\users\Mára\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\users\Mára\AppData\Roaming\Mozilla\Firefox\Profiles\we31b8nu.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components\qippipe.dll
FF - component: c:\users\Mára\AppData\Roaming\Mozilla\Firefox\Profiles\we31b8nu.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-tihud - c:\users\Mára\AppData\Roaming\Microsoft\pujoo.exe
HKCU-Run-zigy - c:\users\Mára\AppData\Roaming\Microsoft\fuhouquou.exe
HKLM-Run-ETDWare - %ProgramFiles%\Elantech\ETDCtrl.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1720832198-948083888-3724728450-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):46,4b,b8,2a,2c,a7,fa,77,3d,ec,a0,54,6a,77,70,46,5b,90,c4,e0,a9,
60,6b,83,47,57,0b,f2,94,2c,98,ed,01,b7,46,20,c9,48,2c,33,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-1720832198-948083888-3724728450-1000_Classes\CLSID\{ad2d4bae-d298-433d-89a3-01ad1b61bd1b}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000145
"Therad"=dword:0000001b
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(556)
c:\program files\ASUS\ASUS Data Security Manager\ASPWDFLT.DLL
- - - - - - - > 'Explorer.exe'(2812)
c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\windows\system32\taskhost.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\ControlDeck\ControlDeck.exe
c:\program files\ASUS\SmartLogon\facemgr.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files\ASUS\ASUS CopyProtect\aspg.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\windows\System32\ACEngSvr.exe
c:\windows\system32\conhost.exe
c:\program files\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2010-11-22 19:46:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-11-22 18:46
Před spuštěním: Volných bajtů: 179 735 752 704
Po spuštění: Volných bajtů: 179 611 987 968
- - End Of File - - A1C8B5B6CB9D270DE45F0B3F4F4618C7

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o pomoc
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o pomoc
Už to funguje.... 

Re: Prosím o pomoc

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Folder:: c:\users\M ra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Collect:: c:\users\Mára\ipuupt.exe c:\users\Mára\hdgqvm.exe c:\users\Mára\AppData\Roaming\juzjf.exe c:\users\Mára\AppData\Roaming\Microsoft\mejoujoo.exe c:\windows\System32\Drivers\nccfbwpe.sys Driver:: eoayaeexee7 nccfbwpe File:: c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"=- "QIP Internet Guardian"=- "Skype"=- Firefox:: FF - ProfilePath - c:\users\Mára\AppData\Roaming\Mozilla\Firefox\Profiles\we31b8nu.default\ FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte

Re: Prosím o pomoc
Tak moc děkuji za pomoc 

Re: Prosím o pomoc
Provedte prosim krok se skriptem pro CF a dejte log, jeste tam nejakou havet mate...