ComboFix 12-02-05.02 - Martin 05.02.2012 10:15:05.4.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.4061.2399 [GMT 1:00]
Spuštěný z: c:\users\Martin\Desktop\ComboFix.exe
AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-05 do 2012-02-05 )))))))))))))))))))))))))))))))
.
.
2012-02-04 23:40 . 2007-05-11 02:12 38160 ----a-w- c:\windows\system32\drivers\blueletaudio.sys
2012-02-04 23:40 . 2007-03-05 04:48 37648 ----a-w- c:\windows\system32\drivers\BlueletSCOAudio.sys
2012-02-04 23:40 . 2007-03-05 04:47 25360 ----a-w- c:\windows\system32\drivers\BtNetDrv.sys
2012-02-04 23:40 . 2007-03-05 04:44 23184 ----a-w- c:\windows\system32\drivers\VHIDMini.sys
2012-02-04 23:40 . 2007-03-05 04:42 49680 ----a-w- c:\windows\system32\drivers\BTHidMgr.sys
2012-02-04 23:40 . 2007-03-05 04:41 24976 ----a-w- c:\windows\system32\drivers\VBTEnum.sys
2012-02-04 23:40 . 2007-03-05 04:39 63248 ----a-w- c:\windows\system32\drivers\VcommMgr.sys
2012-02-04 23:40 . 2007-03-05 04:38 47120 ----a-w- c:\windows\system32\drivers\VComm.sys
2012-02-04 23:40 . 2006-10-08 23:29 32832 ----a-w- c:\windows\system32\drivers\BTNetFilter.sys
2012-02-04 23:29 . 2012-02-04 23:33 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE
2012-02-04 22:15 . 2012-02-04 23:39 -------- d-----w- c:\program files (x86)\IVT Corporation
2012-02-04 19:47 . 2012-02-04 19:47 -------- d-----w- c:\program files (x86)\Clear History
2012-02-04 10:01 . 2012-02-04 10:26 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-02-04 10:01 . 2012-02-04 17:37 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-02-03 12:15 . 2012-02-03 12:15 -------- d-----w- c:\windows\SysWow64\ivtMobCache
2012-02-03 11:07 . 2012-02-04 17:37 -------- d-----w- C:\Uninstall
2012-02-03 10:08 . 2008-05-07 06:39 66560 ----a-w- c:\windows\system32\nmwcdclsx64.dll
2012-02-03 10:08 . 2008-08-28 11:44 25600 ----a-w- c:\windows\system32\drivers\pccsmcfdx64.sys
2012-02-02 20:05 . 2012-02-02 20:05 -------- d-----w- c:\program files (x86)\Nokia
2012-02-02 20:05 . 2012-02-02 20:05 -------- d-----w- c:\program files\DIFX
2012-02-02 20:04 . 2012-02-04 17:37 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2012-02-02 20:04 . 2012-02-02 20:04 -------- d-----w- c:\programdata\Installations
2012-02-02 16:42 . 2012-02-02 16:42 -------- d-----w- C:\$AVG
2012-02-02 16:32 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2012-02-02 16:32 . 2012-02-02 16:32 -------- d-----w- c:\programdata\Malwarebytes
2012-02-02 16:32 . 2012-02-04 23:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-02-02 16:32 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-01 16:21 . 2011-10-17 14:55 559384 ----a-w- c:\windows\system32\drivers\iaStor.sys
2012-02-01 10:54 . 2012-02-01 10:54 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-02-01 10:54 . 2012-02-01 10:54 484176 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-01-31 09:32 . 2012-01-31 09:32 -------- d-----w- c:\program files (x86)\JAM Software
2012-01-30 18:04 . 2012-02-02 23:42 -------- d-----w- c:\windows\system32\appmgmt
2012-01-30 13:10 . 2012-02-04 17:37 -------- d-----w- c:\program files (x86)\ExpressFiles
2012-01-29 22:11 . 2012-01-29 22:11 -------- d-----w- c:\program files (x86)\Nová složka
2012-01-29 22:04 . 2012-01-30 18:27 -------- d-----w- c:\program files (x86)\Innovative Solutions
2012-01-29 21:40 . 2012-01-29 21:40 -------- d-----w- c:\programdata\Innovative Solutions
2012-01-29 21:28 . 2011-10-13 11:10 90112 ----a-w- c:\windows\system32\igfxCoIn_v2555.dll
2012-01-29 21:28 . 2011-10-13 10:30 208896 ----a-w- c:\windows\SysWow64\iglhsip32.dll
2012-01-29 21:28 . 2011-10-13 10:30 206336 ----a-w- c:\windows\system32\iglhsip64.dll
2012-01-29 21:28 . 2011-10-13 10:30 188416 ----a-w- c:\windows\system32\iglhcp64.dll
2012-01-29 21:28 . 2011-10-13 10:30 147456 ----a-w- c:\windows\SysWow64\iglhcp32.dll
2012-01-29 21:23 . 2011-07-27 09:28 42888 ----a-w- c:\windows\system32\drivers\btcusb.sys
2012-01-29 21:23 . 2007-05-09 01:00 16144 ----a-w- c:\windows\system32\btinstall.dll
2012-01-29 19:44 . 2012-01-29 19:44 -------- d-----w- c:\windows\system32\Macromed
2012-01-29 19:19 . 2012-01-29 19:45 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-29 18:28 . 2012-01-29 18:28 -------- d-----w- c:\programdata\ASUS
2012-01-29 10:21 . 2012-01-29 10:22 -------- d-----w- C:\MyBootCD
2012-01-28 23:56 . 2012-01-28 23:57 -------- d-----w- c:\program files (x86)\Common Files\Nero
2012-01-28 23:56 . 2012-01-29 00:01 -------- d-----w- c:\program files (x86)\Nero
2012-01-28 23:24 . 2012-01-28 23:24 -------- d-----w- c:\programdata\ashampoo
2012-01-28 23:24 . 2012-01-28 23:37 -------- d-----w- c:\program files (x86)\Ashampoo
2012-01-28 23:17 . 2012-01-30 18:30 -------- d-----w- c:\program files (x86)\CrystalDiskInfo
2012-01-28 22:39 . 2012-02-02 17:53 -------- d-----w- c:\program files\trend micro
2012-01-28 22:16 . 2012-01-28 22:16 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared
2012-01-28 17:26 . 2012-01-28 17:26 21712 ----a-w- c:\windows\SysWow64\drivers\DrvAgent64.SYS
2012-01-28 17:23 . 2012-01-28 17:32 -------- d-----w- c:\program files (x86)\HWiNFO32
2012-01-28 07:56 . 2012-01-28 07:56 -------- d-----w- c:\programdata\Symantec
2012-01-28 07:56 . 2012-01-28 07:56 -------- d-----w- c:\windows\system32\drivers\NSSx64
2012-01-28 07:56 . 2012-01-28 07:56 -------- d-----w- c:\program files (x86)\Norton Security Scan
2012-01-28 07:56 . 2012-01-28 07:56 -------- d-----w- c:\programdata\Norton
2012-01-28 07:56 . 2012-01-28 07:56 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-01-27 20:46 . 2012-01-30 18:30 -------- d-----w- c:\programdata\McAfee Security Scan
2012-01-27 20:46 . 2012-01-27 20:46 -------- d-----w- c:\programdata\McAfee
2012-01-27 20:46 . 2012-01-27 20:46 -------- d-----w- c:\program files (x86)\McAfee Security Scan
2012-01-27 20:46 . 2012-01-27 20:46 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-01-27 20:43 . 2012-01-27 20:43 -------- d-----w- c:\windows\SysWow64\Adobe
2012-01-27 16:20 . 2012-01-27 16:20 -------- d-----w- C:\NVIDIA
2012-01-27 15:39 . 2010-12-14 15:34 550512 ----a-w- c:\windows\system32\VIASysFx.dll
2012-01-27 15:39 . 2010-12-14 15:34 993392 ----a-w- c:\windows\system32\VIAPropPageExt.dll
2012-01-27 15:39 . 2010-12-14 15:34 86640 ----a-w- c:\windows\system32\ViaMicArrayPropPageExt.dll
2012-01-27 15:39 . 2010-12-14 15:34 202864 ----a-w- c:\windows\system32\ViaMicArrayAPO.dll
2012-01-27 15:39 . 2010-12-14 15:34 27760 ----a-w- c:\windows\system32\ViakaraokeSrv.exe
2012-01-27 15:39 . 2010-12-14 15:34 1357424 ----a-w- c:\windows\system32\drivers\viahduaa.sys
2012-01-27 15:39 . 2010-12-14 15:34 123504 ----a-w- c:\windows\system32\ViaKaraokeApo.dll
2012-01-27 15:39 . 2010-12-14 15:34 91760 ----a-w- c:\windows\system32\Dts2PropPageExt.dll
2012-01-27 15:39 . 2010-12-14 15:34 116848 ----a-w- c:\windows\system32\ViaKaraokePropPageExt.dll
2012-01-27 15:39 . 2010-12-14 15:34 248944 ----a-w- c:\windows\system32\Dts2APO.dll
2012-01-27 15:39 . 2011-09-21 09:25 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x64.sys
2012-01-27 15:39 . 2012-01-27 15:39 -------- d-----w- c:\program files\CPUID
2012-01-27 15:36 . 2012-01-27 15:37 -------- d-----w- c:\program files (x86)\audio
2012-01-27 15:21 . 2012-01-27 15:21 -------- d-----w- c:\windows\SysWow64\Atheros_L1e
2012-01-27 15:19 . 2012-01-30 18:30 -------- d-----w- c:\programdata\FLEXnet
2012-01-27 15:19 . 2010-06-30 11:02 52736 ----a-w- c:\windows\system32\drivers\btmcom.sys
2012-01-27 15:18 . 2012-01-30 18:30 -------- d-----w- c:\program files\Motorola
2012-01-27 15:18 . 2010-07-28 16:52 476928 ----a-w- c:\windows\system32\drivers\btmusb.sys
2012-01-27 15:18 . 2010-07-15 11:22 323848 ----a-w- c:\windows\system32\btmcls.dll
2012-01-27 15:18 . 2012-01-30 18:30 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2012-01-27 15:18 . 2012-01-30 18:30 -------- d-----w- c:\program files (x86)\Common Files\Macrovision Shared
2012-01-27 15:08 . 2012-01-27 15:08 -------- d-----w- c:\program files (x86)\Driver-Soft
2012-01-25 20:31 . 2012-01-25 20:31 -------- d-----w- c:\program files (x86)\ESET
2012-01-25 16:07 . 2012-01-25 16:07 243 ----a-w- C:\user.js
2012-01-25 16:07 . 2012-01-25 16:07 -------- d-----w- c:\programdata\Babylon
2012-01-25 16:07 . 2012-01-25 16:07 -------- d-----w- c:\program files\Logon Screen
2012-01-22 20:25 . 2009-09-04 16:29 235344 ----a-w- c:\windows\SysWow64\d3dx11_42.dll
2012-01-22 20:24 . 2008-07-10 10:00 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-22 20:19 . 2011-11-02 22:08 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-01-22 20:19 . 2011-11-02 21:09 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-01-22 20:18 . 2012-01-22 20:21 -------- d--h--w- c:\windows\msdownld.tmp
2012-01-22 13:31 . 2012-01-22 13:31 -------- d-----w- c:\program files (x86)\FastStone Image Viewer
2012-01-22 13:23 . 2012-01-22 13:23 -------- d-----w- c:\program files (x86)\Lamer
2012-01-22 13:14 . 2011-11-28 13:51 33872 ----a-w- c:\windows\system32\drivers\anvsnddrv.sys
2012-01-22 13:14 . 2011-11-28 13:51 235520 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2012-01-22 13:14 . 2011-11-28 13:51 632832 ----a-w- c:\windows\SysWow64\xvidcore.dll
2012-01-22 13:14 . 2011-11-28 13:51 143872 ----a-w- c:\windows\SysWow64\xvid.ax
2012-01-22 13:11 . 2012-01-22 13:27 -------- d-----w- c:\program files (x86)\AnvSoft
2012-01-22 13:09 . 2012-01-22 13:09 -------- d-----w- c:\program files (x86)\Conduit
2012-01-22 12:55 . 2012-01-22 12:55 -------- d-----w- c:\windows\system32\SPReview
2012-01-22 11:55 . 2012-01-22 11:55 -------- d-----w- c:\windows\system32\EventProviders
2012-01-22 11:52 . 2010-11-20 13:27 2086912 ----a-w- c:\windows\system32\ole32.dll
2012-01-22 11:51 . 2010-11-20 13:27 1246720 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2012-01-22 11:50 . 2010-11-20 13:27 1808384 ----a-w- c:\windows\system32\pnidui.dll
2012-01-22 11:49 . 2010-11-20 13:27 244224 ----a-w- c:\windows\system32\spp.dll
2012-01-22 11:48 . 2010-11-20 13:24 442368 ----a-w- c:\windows\system32\winspool.drv
2012-01-22 11:47 . 2010-11-20 13:28 166784 ----a-w- c:\windows\system32\basecsp.dll
2012-01-22 11:46 . 2010-11-20 13:27 172544 ----a-w- c:\windows\system32\twext.dll
2012-01-22 11:45 . 2010-11-20 13:27 37376 ----a-w- c:\windows\system32\shimgvw.dll
2012-01-22 11:44 . 2010-11-20 13:33 6656 ----a-w- c:\windows\system32\drivers\cs-CZ\rdvgkmd.sys.mui
2012-01-22 11:44 . 2010-11-20 13:25 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbhub.sys.mui
2012-01-22 11:44 . 2010-11-20 13:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
2012-01-22 11:44 . 2010-11-20 13:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
2012-01-22 11:44 . 2010-11-20 13:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2012-01-22 11:44 . 2010-11-20 13:31 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2012-01-22 11:44 . 2010-11-20 13:43 3584 ----a-w- c:\windows\system32\drivers\pl-PL\tsusbflt.sys.mui
2012-01-22 11:44 . 2010-11-20 13:41 6656 ----a-w- c:\windows\system32\drivers\pl-PL\rdvgkmd.sys.mui
2012-01-22 11:44 . 2010-11-20 13:38 4608 ----a-w- c:\windows\system32\drivers\pl-PL\tsusbhub.sys.mui
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-22 14:03 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-01-22 14:03 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-01-21 19:30 . 2012-01-21 19:30 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2012-01-21 19:30 . 2012-01-21 19:30 249344 ----a-w- c:\windows\system32\webcheck.dll
2011-12-06 14:55 . 2010-04-20 04:30 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-12-22 2870896]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-08-20 170624]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-01-21 296056]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2010-4-20 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-4-20 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"Guard.Mail.ru.gui"="c:\program files (x86)\Guard-ICQ\GuardICQ.exe" /gui
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\program files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
"ExpressFiles"="c:\program files (x86)\ExpressFiles\ExpressFiles.exe" -tray
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [x]
R3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [x]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [2012-01-28 21712]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-01-27 1028096]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-20 135664]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-20 135664]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\program files (x86)\HWiNFO32\HWiNFO64A.SYS [2011-12-19 30080]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files (x86)\Guard-ICQ\GuardICQ.exe [2012-01-21 1564368]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2011-12-08 2123584]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [x]
S3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys [x]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2011-11-08 11856]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-20 04:11]
.
2012-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-20 04:11]
.
2012-01-28 c:\windows\Tasks\Norton Security Scan for Martin.job
- c:\progra~2\NORTON~2\Engine\370~1.18\Nss.exe [2012-01-28 10:01]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2009-12-24 1736704]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-10-13 162584]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-10-13 386840]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\x22ecfqi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=100789&babsrc=adbartrp&mntrId=0cdd3cc500000000000000158330973c&q=
FF - prefs.js: network.proxy.http - 58.58.180.122
FF - prefs.js: network.proxy.type - 1
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=100789
FF - user.js: extensions.BabylonToolbar_i.babExt - somoto
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 0cdd3cc500000000000000158330973c
FF - user.js: extensions.BabylonToolbar_i.hardId - 0cdd3cc500000000000000158330973c
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15364
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1717:07
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb5
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-02-05 10:28:20
ComboFix-quarantined-files.txt 2012-02-05 09:28
.
Před spuštěním: Volných bajtů: 407 414 321 152
Po spuštění: Volných bajtů: 407 281 987 584
.
- - End Of File - - 22B3C132F1B21A383C54E48795495D2A