Re: svchost.exe prestal pracovat
Napsal: 30 pro 2010 19:53
Ešte ze mám ten mobil
ComboFix 10-12-29.04 - Tokyto 30.12.2010 19:10:28.2.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.988 [GMT 1:00]
Spu�t�n� z: c:\users\Tokyto\Desktop\ComboFix.exe
Pou�it� ovl�dac� p�ep�na�e :: c:\users\Tokyto\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job"
.
((((((((((((((((((((((((((((((((((((((( Ostatn� v�mazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job
.
((((((((((((((((((((((((((((((((((((((( Ovlada�e/Slu�by )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EHDRV
-------\Legacy_EPFWWFPR
-------\Service_ehdrv
-------\Service_epfwwfpr
((((((((((((((((((((((((( Soubory vytvo�en� od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 16:29 . 2010-12-30 16:29 -------- d-----w- c:\users\Tokyto\AppData\Roaming\.minecraft
2010-12-30 15:00 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-30 15:00 . 2010-09-07 16:11 167592 ----a-w- c:\windows\SysWow64\aswBoot.exe
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\programdata\Alwil Software
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\program files\Alwil Software
2010-12-30 11:30 . 2010-11-10 05:35 8199504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{949FBF4A-EED2-4D6E-BA29-0B6B59C3A423}\mpengine.dll
2010-12-29 18:19 . 2010-12-29 18:19 -------- d-----w- c:\program files (x86)\Realtek
2010-12-29 18:10 . 2010-12-29 18:10 -------- d-----w- c:\program files (x86)\Common Files\Java
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2010-12-28 19:28 . 2010-12-28 19:28 388096 ----a-r- c:\users\Tokyto\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-28 19:28 . 2010-12-28 19:28 -------- d-----w- c:\program files (x86)\Trend Micro
2010-12-18 22:02 . 2010-12-30 12:12 -------- d-----w- c:\program files (x86)\A1 WMA Tools
2010-12-18 21:38 . 2003-03-26 05:59 573440 ----a-w- c:\windows\SysWow64\NCTAudioInformation2.dll
2010-12-18 21:38 . 2003-03-25 14:08 286720 ----a-w- c:\windows\SysWow64\NCTWMAFile2.dll
2010-12-18 21:38 . 2002-12-03 02:11 143872 ----a-w- c:\windows\SysWow64\NCTWMAFile.dll
2010-12-18 21:38 . 2002-12-03 02:07 168448 ----a-w- c:\windows\SysWow64\NCTAudioPlayer.dll
2010-12-18 21:38 . 2002-12-03 02:02 491520 ----a-w- c:\windows\SysWow64\NCTAudioFile.dll
2010-12-18 21:38 . 2002-01-05 06:37 344064 ----a-w- c:\windows\SysWow64\msvcr70.dll
2010-12-18 13:09 . 2010-12-18 13:09 -------- d-----w- c:\program files (x86)\NAVIGON
2010-12-14 18:43 . 2010-12-14 18:44 -------- d-----w- c:\users\Tokyto\AppData\Roaming\zaloha minecraft�
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\IsolatedStorage
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\Futuremark_Corporation
2010-12-07 18:35 . 2010-12-07 18:35 -------- d-----w- c:\program files (x86)\Common Files\Futuremark Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M v�pis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 20:11 . 2010-01-26 18:09 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2010-12-16 20:11 . 2010-01-26 18:09 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2010-11-13 11:48 . 2010-01-26 18:54 234392 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2010-11-05 13:05 . 2010-11-05 13:05 2427248 ----a-w- c:\windows\SysWow64\pbsvc_heroes.exe
2010-10-16 18:55 . 2010-10-29 13:54 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2010-10-16 18:55 . 2010-10-29 13:54 5473896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2010-10-16 18:55 . 2010-10-29 13:54 4837480 ----a-w- c:\windows\SysWow64\nvcuda.dll
2010-10-16 18:55 . 2010-10-29 13:54 319080 ----a-w- c:\windows\SysWow64\nvdecodemft.dll
2010-10-16 18:55 . 2010-10-29 13:54 2912360 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2010-10-16 18:55 . 2010-10-29 13:54 2666600 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2010-10-16 18:55 . 2010-10-29 13:54 14899816 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2010-10-16 18:55 . 2010-10-29 13:54 1719912 ----a-w- c:\windows\SysWow64\nvapi.dll
2010-10-16 18:55 . 2010-10-29 13:54 13019752 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2010-10-16 18:55 . 2010-03-20 12:01 10023528 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2010-10-14 00:36 . 2010-10-14 00:36 15451288 ----a-w- c:\windows\SysWow64\xlive.dll
2010-10-14 00:36 . 2010-10-14 00:36 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2010-09-12 13:57 . 2010-09-12 13:36 814143398 ----a-w- c:\program files (x86)\loleusetup.exe
2010-04-22 12:32 . 2010-03-28 15:12 704282 ----a-w- c:\program files (x86)\unins000.exe
2010-04-02 12:45 . 2010-04-02 12:10 473 ----a-w- c:\program files (x86)\layout.bin
2010-04-02 12:45 . 2010-04-02 12:10 576000 ----a-w- c:\program files (x86)\ISSetup.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-30_17.02.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 05:01 . 2010-12-30 18:21 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2010-12-30 12:00 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-04-28 16:00 . 2010-12-30 18:21 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
- 2010-04-28 16:00 . 2010-12-29 21:01 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spou�t�c� body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Pozn�mka* pr�zdn� z�znamy a legitimn� v�choz� �daje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Infium"="c:\program files (x86)\QIP Infium\infium.exe" [2010-09-06 5896656]
"DriverMax"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"DriverMax_RESTART"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 908160]
c:\users\Tokyto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files (x86)\Xfire\Xfire.exe [2010-7-9 3493776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"NokiaMServer"=c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-11-11 128928]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena\plugins\UI\safedrv.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [2010-02-26 25088]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [2010-02-26 19456]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Slu�ba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-24 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-26 834544]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008]
S2 GS In-Game Service;GS In-Game Service;c:\program files (x86)\GameTracker\GSInGameService.exe [2009-12-10 1643872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-02-11 172328]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-17 1394504]
S2 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2010-11-22 718072]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-11 408680]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2009-11-09 35112]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF7458.cfxxe" [X]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Dopl�kov� sken -------
.
uLocal Page = c:\windows\SYSTEM32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: {76408C75-C11F-4AFC-9C77-C4289F0CC8DE} = 192.168.2.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
.
.
--------------------- ZAMKNUT� KL��E V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:62,11,cd,be,b2,6a,22,42,ea,70,7f,e6,62,fe,61,5a,d6,99,02,4c,7b,5b,10,
92,2d,74,16,a4,0d,c2,76,4c,8b,1f,b5,f3,2c,05,ae,6d,5c,10,4f,18,8d,f5,71,cd,\
"??"=hex:c3,26,06,7f,34,67,ca,e0,4f,9e,cb,24,ea,da,30,eb
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\License information*]
"datasecu"=hex:f7,df,3c,eb,4c,90,48,8d,54,d6,7d,50,fc,ff,cb,ae,74,af,b5,54,22,
eb,03,0b,28,23,58,ea,d6,7d,b1,16,0e,79,19,a8,f1,a6,b3,8d,22,7c,f9,b5,db,b4,\
"rkeysecu"=hex:a7,fd,be,5f,3a,22,f5,0a,8e,68,9a,f8,72,f3,90,8d
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Jin� spu�ten� procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
.
**************************************************************************
.
Celkov� �as: 2010-12-30 19:30:05 - po��ta� byl restartov�n
ComboFix-quarantined-files.txt 2010-12-30 18:30
ComboFix2.txt 2010-12-30 17:19
P�ed spu�t�n�m: Voln�ch bajt�: 18�125�516�800
Po spu�t�n�: Voln�ch bajt�: 17�792�950�272
- - End Of File - - CEF58C0C090F62BB19248BAF91F05BD6
ComboFix 10-12-29.04 - Tokyto 30.12.2010 19:10:28.2.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.988 [GMT 1:00]
Spu�t�n� z: c:\users\Tokyto\Desktop\ComboFix.exe
Pou�it� ovl�dac� p�ep�na�e :: c:\users\Tokyto\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job"
.
((((((((((((((((((((((((((((((((((((((( Ostatn� v�mazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job
.
((((((((((((((((((((((((((((((((((((((( Ovlada�e/Slu�by )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EHDRV
-------\Legacy_EPFWWFPR
-------\Service_ehdrv
-------\Service_epfwwfpr
((((((((((((((((((((((((( Soubory vytvo�en� od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 16:29 . 2010-12-30 16:29 -------- d-----w- c:\users\Tokyto\AppData\Roaming\.minecraft
2010-12-30 15:00 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-30 15:00 . 2010-09-07 16:11 167592 ----a-w- c:\windows\SysWow64\aswBoot.exe
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\programdata\Alwil Software
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\program files\Alwil Software
2010-12-30 11:30 . 2010-11-10 05:35 8199504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{949FBF4A-EED2-4D6E-BA29-0B6B59C3A423}\mpengine.dll
2010-12-29 18:19 . 2010-12-29 18:19 -------- d-----w- c:\program files (x86)\Realtek
2010-12-29 18:10 . 2010-12-29 18:10 -------- d-----w- c:\program files (x86)\Common Files\Java
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2010-12-28 19:28 . 2010-12-28 19:28 388096 ----a-r- c:\users\Tokyto\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-28 19:28 . 2010-12-28 19:28 -------- d-----w- c:\program files (x86)\Trend Micro
2010-12-18 22:02 . 2010-12-30 12:12 -------- d-----w- c:\program files (x86)\A1 WMA Tools
2010-12-18 21:38 . 2003-03-26 05:59 573440 ----a-w- c:\windows\SysWow64\NCTAudioInformation2.dll
2010-12-18 21:38 . 2003-03-25 14:08 286720 ----a-w- c:\windows\SysWow64\NCTWMAFile2.dll
2010-12-18 21:38 . 2002-12-03 02:11 143872 ----a-w- c:\windows\SysWow64\NCTWMAFile.dll
2010-12-18 21:38 . 2002-12-03 02:07 168448 ----a-w- c:\windows\SysWow64\NCTAudioPlayer.dll
2010-12-18 21:38 . 2002-12-03 02:02 491520 ----a-w- c:\windows\SysWow64\NCTAudioFile.dll
2010-12-18 21:38 . 2002-01-05 06:37 344064 ----a-w- c:\windows\SysWow64\msvcr70.dll
2010-12-18 13:09 . 2010-12-18 13:09 -------- d-----w- c:\program files (x86)\NAVIGON
2010-12-14 18:43 . 2010-12-14 18:44 -------- d-----w- c:\users\Tokyto\AppData\Roaming\zaloha minecraft�
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\IsolatedStorage
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\Futuremark_Corporation
2010-12-07 18:35 . 2010-12-07 18:35 -------- d-----w- c:\program files (x86)\Common Files\Futuremark Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M v�pis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 20:11 . 2010-01-26 18:09 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2010-12-16 20:11 . 2010-01-26 18:09 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2010-11-13 11:48 . 2010-01-26 18:54 234392 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2010-11-05 13:05 . 2010-11-05 13:05 2427248 ----a-w- c:\windows\SysWow64\pbsvc_heroes.exe
2010-10-16 18:55 . 2010-10-29 13:54 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2010-10-16 18:55 . 2010-10-29 13:54 5473896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2010-10-16 18:55 . 2010-10-29 13:54 4837480 ----a-w- c:\windows\SysWow64\nvcuda.dll
2010-10-16 18:55 . 2010-10-29 13:54 319080 ----a-w- c:\windows\SysWow64\nvdecodemft.dll
2010-10-16 18:55 . 2010-10-29 13:54 2912360 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2010-10-16 18:55 . 2010-10-29 13:54 2666600 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2010-10-16 18:55 . 2010-10-29 13:54 14899816 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2010-10-16 18:55 . 2010-10-29 13:54 1719912 ----a-w- c:\windows\SysWow64\nvapi.dll
2010-10-16 18:55 . 2010-10-29 13:54 13019752 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2010-10-16 18:55 . 2010-03-20 12:01 10023528 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2010-10-14 00:36 . 2010-10-14 00:36 15451288 ----a-w- c:\windows\SysWow64\xlive.dll
2010-10-14 00:36 . 2010-10-14 00:36 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2010-09-12 13:57 . 2010-09-12 13:36 814143398 ----a-w- c:\program files (x86)\loleusetup.exe
2010-04-22 12:32 . 2010-03-28 15:12 704282 ----a-w- c:\program files (x86)\unins000.exe
2010-04-02 12:45 . 2010-04-02 12:10 473 ----a-w- c:\program files (x86)\layout.bin
2010-04-02 12:45 . 2010-04-02 12:10 576000 ----a-w- c:\program files (x86)\ISSetup.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-30_17.02.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 05:01 . 2010-12-30 18:21 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2010-12-30 12:00 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-04-28 16:00 . 2010-12-30 18:21 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
- 2010-04-28 16:00 . 2010-12-29 21:01 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spou�t�c� body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Pozn�mka* pr�zdn� z�znamy a legitimn� v�choz� �daje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Infium"="c:\program files (x86)\QIP Infium\infium.exe" [2010-09-06 5896656]
"DriverMax"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"DriverMax_RESTART"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 908160]
c:\users\Tokyto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files (x86)\Xfire\Xfire.exe [2010-7-9 3493776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"NokiaMServer"=c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-11-11 128928]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena\plugins\UI\safedrv.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [2010-02-26 25088]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [2010-02-26 19456]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Slu�ba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-24 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-26 834544]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008]
S2 GS In-Game Service;GS In-Game Service;c:\program files (x86)\GameTracker\GSInGameService.exe [2009-12-10 1643872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-02-11 172328]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-17 1394504]
S2 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2010-11-22 718072]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-11 408680]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2009-11-09 35112]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF7458.cfxxe" [X]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Dopl�kov� sken -------
.
uLocal Page = c:\windows\SYSTEM32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: {76408C75-C11F-4AFC-9C77-C4289F0CC8DE} = 192.168.2.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
.
.
--------------------- ZAMKNUT� KL��E V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:62,11,cd,be,b2,6a,22,42,ea,70,7f,e6,62,fe,61,5a,d6,99,02,4c,7b,5b,10,
92,2d,74,16,a4,0d,c2,76,4c,8b,1f,b5,f3,2c,05,ae,6d,5c,10,4f,18,8d,f5,71,cd,\
"??"=hex:c3,26,06,7f,34,67,ca,e0,4f,9e,cb,24,ea,da,30,eb
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\License information*]
"datasecu"=hex:f7,df,3c,eb,4c,90,48,8d,54,d6,7d,50,fc,ff,cb,ae,74,af,b5,54,22,
eb,03,0b,28,23,58,ea,d6,7d,b1,16,0e,79,19,a8,f1,a6,b3,8d,22,7c,f9,b5,db,b4,\
"rkeysecu"=hex:a7,fd,be,5f,3a,22,f5,0a,8e,68,9a,f8,72,f3,90,8d
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Jin� spu�ten� procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
.
**************************************************************************
.
Celkov� �as: 2010-12-30 19:30:05 - po��ta� byl restartov�n
ComboFix-quarantined-files.txt 2010-12-30 18:30
ComboFix2.txt 2010-12-30 17:19
P�ed spu�t�n�m: Voln�ch bajt�: 18�125�516�800
Po spu�t�n�: Voln�ch bajt�: 17�792�950�272
- - End Of File - - CEF58C0C090F62BB19248BAF91F05BD6
ComboFix 10-12-29.04 - Tokyto 30.12.2010 19:10:28.2.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.988 [GMT 1:00]
Spu�t�n� z: c:\users\Tokyto\Desktop\ComboFix.exe
Pou�it� ovl�dac� p�ep�na�e :: c:\users\Tokyto\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job"
.
((((((((((((((((((((((((((((((((((((((( Ostatn� v�mazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job
.
((((((((((((((((((((((((((((((((((((((( Ovlada�e/Slu�by )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EHDRV
-------\Legacy_EPFWWFPR
-------\Service_ehdrv
-------\Service_epfwwfpr
((((((((((((((((((((((((( Soubory vytvo�en� od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 16:29 . 2010-12-30 16:29 -------- d-----w- c:\users\Tokyto\AppData\Roaming\.minecraft
2010-12-30 15:00 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-30 15:00 . 2010-09-07 16:11 167592 ----a-w- c:\windows\SysWow64\aswBoot.exe
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\programdata\Alwil Software
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\program files\Alwil Software
2010-12-30 11:30 . 2010-11-10 05:35 8199504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{949FBF4A-EED2-4D6E-BA29-0B6B59C3A423}\mpengine.dll
2010-12-29 18:19 . 2010-12-29 18:19 -------- d-----w- c:\program files (x86)\Realtek
2010-12-29 18:10 . 2010-12-29 18:10 -------- d-----w- c:\program files (x86)\Common Files\Java
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2010-12-28 19:28 . 2010-12-28 19:28 388096 ----a-r- c:\users\Tokyto\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-28 19:28 . 2010-12-28 19:28 -------- d-----w- c:\program files (x86)\Trend Micro
2010-12-18 22:02 . 2010-12-30 12:12 -------- d-----w- c:\program files (x86)\A1 WMA Tools
2010-12-18 21:38 . 2003-03-26 05:59 573440 ----a-w- c:\windows\SysWow64\NCTAudioInformation2.dll
2010-12-18 21:38 . 2003-03-25 14:08 286720 ----a-w- c:\windows\SysWow64\NCTWMAFile2.dll
2010-12-18 21:38 . 2002-12-03 02:11 143872 ----a-w- c:\windows\SysWow64\NCTWMAFile.dll
2010-12-18 21:38 . 2002-12-03 02:07 168448 ----a-w- c:\windows\SysWow64\NCTAudioPlayer.dll
2010-12-18 21:38 . 2002-12-03 02:02 491520 ----a-w- c:\windows\SysWow64\NCTAudioFile.dll
2010-12-18 21:38 . 2002-01-05 06:37 344064 ----a-w- c:\windows\SysWow64\msvcr70.dll
2010-12-18 13:09 . 2010-12-18 13:09 -------- d-----w- c:\program files (x86)\NAVIGON
2010-12-14 18:43 . 2010-12-14 18:44 -------- d-----w- c:\users\Tokyto\AppData\Roaming\zaloha minecraft�
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\IsolatedStorage
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\Futuremark_Corporation
2010-12-07 18:35 . 2010-12-07 18:35 -------- d-----w- c:\program files (x86)\Common Files\Futuremark Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M v�pis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 20:11 . 2010-01-26 18:09 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2010-12-16 20:11 . 2010-01-26 18:09 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2010-11-13 11:48 . 2010-01-26 18:54 234392 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2010-11-05 13:05 . 2010-11-05 13:05 2427248 ----a-w- c:\windows\SysWow64\pbsvc_heroes.exe
2010-10-16 18:55 . 2010-10-29 13:54 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2010-10-16 18:55 . 2010-10-29 13:54 5473896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2010-10-16 18:55 . 2010-10-29 13:54 4837480 ----a-w- c:\windows\SysWow64\nvcuda.dll
2010-10-16 18:55 . 2010-10-29 13:54 319080 ----a-w- c:\windows\SysWow64\nvdecodemft.dll
2010-10-16 18:55 . 2010-10-29 13:54 2912360 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2010-10-16 18:55 . 2010-10-29 13:54 2666600 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2010-10-16 18:55 . 2010-10-29 13:54 14899816 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2010-10-16 18:55 . 2010-10-29 13:54 1719912 ----a-w- c:\windows\SysWow64\nvapi.dll
2010-10-16 18:55 . 2010-10-29 13:54 13019752 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2010-10-16 18:55 . 2010-03-20 12:01 10023528 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2010-10-14 00:36 . 2010-10-14 00:36 15451288 ----a-w- c:\windows\SysWow64\xlive.dll
2010-10-14 00:36 . 2010-10-14 00:36 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2010-09-12 13:57 . 2010-09-12 13:36 814143398 ----a-w- c:\program files (x86)\loleusetup.exe
2010-04-22 12:32 . 2010-03-28 15:12 704282 ----a-w- c:\program files (x86)\unins000.exe
2010-04-02 12:45 . 2010-04-02 12:10 473 ----a-w- c:\program files (x86)\layout.bin
2010-04-02 12:45 . 2010-04-02 12:10 576000 ----a-w- c:\program files (x86)\ISSetup.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-30_17.02.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 05:01 . 2010-12-30 18:21 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2010-12-30 12:00 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-04-28 16:00 . 2010-12-30 18:21 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
- 2010-04-28 16:00 . 2010-12-29 21:01 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spou�t�c� body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Pozn�mka* pr�zdn� z�znamy a legitimn� v�choz� �daje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Infium"="c:\program files (x86)\QIP Infium\infium.exe" [2010-09-06 5896656]
"DriverMax"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"DriverMax_RESTART"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 908160]
c:\users\Tokyto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files (x86)\Xfire\Xfire.exe [2010-7-9 3493776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"NokiaMServer"=c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-11-11 128928]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena\plugins\UI\safedrv.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [2010-02-26 25088]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [2010-02-26 19456]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Slu�ba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-24 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-26 834544]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008]
S2 GS In-Game Service;GS In-Game Service;c:\program files (x86)\GameTracker\GSInGameService.exe [2009-12-10 1643872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-02-11 172328]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-17 1394504]
S2 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2010-11-22 718072]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-11 408680]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2009-11-09 35112]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF7458.cfxxe" [X]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Dopl�kov� sken -------
.
uLocal Page = c:\windows\SYSTEM32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: {76408C75-C11F-4AFC-9C77-C4289F0CC8DE} = 192.168.2.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
.
.
--------------------- ZAMKNUT� KL��E V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:62,11,cd,be,b2,6a,22,42,ea,70,7f,e6,62,fe,61,5a,d6,99,02,4c,7b,5b,10,
92,2d,74,16,a4,0d,c2,76,4c,8b,1f,b5,f3,2c,05,ae,6d,5c,10,4f,18,8d,f5,71,cd,\
"??"=hex:c3,26,06,7f,34,67,ca,e0,4f,9e,cb,24,ea,da,30,eb
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\License information*]
"datasecu"=hex:f7,df,3c,eb,4c,90,48,8d,54,d6,7d,50,fc,ff,cb,ae,74,af,b5,54,22,
eb,03,0b,28,23,58,ea,d6,7d,b1,16,0e,79,19,a8,f1,a6,b3,8d,22,7c,f9,b5,db,b4,\
"rkeysecu"=hex:a7,fd,be,5f,3a,22,f5,0a,8e,68,9a,f8,72,f3,90,8d
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Jin� spu�ten� procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
.
**************************************************************************
.
Celkov� �as: 2010-12-30 19:30:05 - po��ta� byl restartov�n
ComboFix-quarantined-files.txt 2010-12-30 18:30
ComboFix2.txt 2010-12-30 17:19
P�ed spu�t�n�m: Voln�ch bajt�: 18�125�516�800
Po spu�t�n�: Voln�ch bajt�: 17�792�950�272
- - End Of File - - CEF58C0C090F62BB19248BAF91F05BD6
ComboFix 10-12-29.04 - Tokyto 30.12.2010 19:10:28.2.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.988 [GMT 1:00]
Spu�t�n� z: c:\users\Tokyto\Desktop\ComboFix.exe
Pou�it� ovl�dac� p�ep�na�e :: c:\users\Tokyto\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job"
.
((((((((((((((((((((((((((((((((((((((( Ostatn� v�mazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3049775063-532791586-3059231688-1001UA.job
.
((((((((((((((((((((((((((((((((((((((( Ovlada�e/Slu�by )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EHDRV
-------\Legacy_EPFWWFPR
-------\Service_ehdrv
-------\Service_epfwwfpr
((((((((((((((((((((((((( Soubory vytvo�en� od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 16:29 . 2010-12-30 16:29 -------- d-----w- c:\users\Tokyto\AppData\Roaming\.minecraft
2010-12-30 15:00 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-30 15:00 . 2010-09-07 16:11 167592 ----a-w- c:\windows\SysWow64\aswBoot.exe
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\programdata\Alwil Software
2010-12-30 14:59 . 2010-12-30 15:00 -------- d-----w- c:\program files\Alwil Software
2010-12-30 11:30 . 2010-11-10 05:35 8199504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{949FBF4A-EED2-4D6E-BA29-0B6B59C3A423}\mpengine.dll
2010-12-29 18:19 . 2010-12-29 18:19 -------- d-----w- c:\program files (x86)\Realtek
2010-12-29 18:10 . 2010-12-29 18:10 -------- d-----w- c:\program files (x86)\Common Files\Java
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-12-29 18:10 . 2010-11-12 17:53 472808 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2010-12-28 19:28 . 2010-12-28 19:28 388096 ----a-r- c:\users\Tokyto\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-28 19:28 . 2010-12-28 19:28 -------- d-----w- c:\program files (x86)\Trend Micro
2010-12-18 22:02 . 2010-12-30 12:12 -------- d-----w- c:\program files (x86)\A1 WMA Tools
2010-12-18 21:38 . 2003-03-26 05:59 573440 ----a-w- c:\windows\SysWow64\NCTAudioInformation2.dll
2010-12-18 21:38 . 2003-03-25 14:08 286720 ----a-w- c:\windows\SysWow64\NCTWMAFile2.dll
2010-12-18 21:38 . 2002-12-03 02:11 143872 ----a-w- c:\windows\SysWow64\NCTWMAFile.dll
2010-12-18 21:38 . 2002-12-03 02:07 168448 ----a-w- c:\windows\SysWow64\NCTAudioPlayer.dll
2010-12-18 21:38 . 2002-12-03 02:02 491520 ----a-w- c:\windows\SysWow64\NCTAudioFile.dll
2010-12-18 21:38 . 2002-01-05 06:37 344064 ----a-w- c:\windows\SysWow64\msvcr70.dll
2010-12-18 13:09 . 2010-12-18 13:09 -------- d-----w- c:\program files (x86)\NAVIGON
2010-12-14 18:43 . 2010-12-14 18:44 -------- d-----w- c:\users\Tokyto\AppData\Roaming\zaloha minecraft�
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\IsolatedStorage
2010-12-07 18:36 . 2010-12-07 18:36 -------- d-----w- c:\users\Tokyto\AppData\Local\Futuremark_Corporation
2010-12-07 18:35 . 2010-12-07 18:35 -------- d-----w- c:\program files (x86)\Common Files\Futuremark Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M v�pis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 20:11 . 2010-01-26 18:09 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2010-12-16 20:11 . 2010-01-26 18:09 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2010-11-13 11:48 . 2010-01-26 18:54 234392 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2010-11-05 13:05 . 2010-11-05 13:05 2427248 ----a-w- c:\windows\SysWow64\pbsvc_heroes.exe
2010-10-16 18:55 . 2010-10-29 13:54 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2010-10-16 18:55 . 2010-10-29 13:54 5473896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2010-10-16 18:55 . 2010-10-29 13:54 4837480 ----a-w- c:\windows\SysWow64\nvcuda.dll
2010-10-16 18:55 . 2010-10-29 13:54 319080 ----a-w- c:\windows\SysWow64\nvdecodemft.dll
2010-10-16 18:55 . 2010-10-29 13:54 2912360 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2010-10-16 18:55 . 2010-10-29 13:54 2666600 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2010-10-16 18:55 . 2010-10-29 13:54 14899816 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2010-10-16 18:55 . 2010-10-29 13:54 1719912 ----a-w- c:\windows\SysWow64\nvapi.dll
2010-10-16 18:55 . 2010-10-29 13:54 13019752 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2010-10-16 18:55 . 2010-03-20 12:01 10023528 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2010-10-14 00:36 . 2010-10-14 00:36 15451288 ----a-w- c:\windows\SysWow64\xlive.dll
2010-10-14 00:36 . 2010-10-14 00:36 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
2010-09-12 13:57 . 2010-09-12 13:36 814143398 ----a-w- c:\program files (x86)\loleusetup.exe
2010-04-22 12:32 . 2010-03-28 15:12 704282 ----a-w- c:\program files (x86)\unins000.exe
2010-04-02 12:45 . 2010-04-02 12:10 473 ----a-w- c:\program files (x86)\layout.bin
2010-04-02 12:45 . 2010-04-02 12:10 576000 ----a-w- c:\program files (x86)\ISSetup.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-30_17.02.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-30 12:02 . 2010-12-30 12:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-30 18:23 . 2010-12-30 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 05:01 . 2010-12-30 18:21 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2010-12-30 12:00 435156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-04-28 16:00 . 2010-12-30 18:21 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
- 2010-04-28 16:00 . 2010-12-29 21:01 8307088 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3049775063-532791586-3059231688-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spou�t�c� body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Pozn�mka* pr�zdn� z�znamy a legitimn� v�choz� �daje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Infium"="c:\program files (x86)\QIP Infium\infium.exe" [2010-09-06 5896656]
"DriverMax"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"DriverMax_RESTART"="c:\program files (x86)\Innovative Solutions\DriverMax\devices.exe" [2010-03-01 9216928]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 908160]
c:\users\Tokyto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files (x86)\Xfire\Xfire.exe [2010-7-9 3493776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"NokiaMServer"=c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-11-11 128928]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena\plugins\UI\safedrv.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [2010-02-26 25088]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [2010-02-26 19456]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Slu�ba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-24 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-26 834544]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008]
S2 GS In-Game Service;GS In-Game Service;c:\program files (x86)\GameTracker\GSInGameService.exe [2009-12-10 1643872]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-02-11 172328]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-17 1394504]
S2 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2010-11-22 718072]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-11 408680]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2009-11-09 35112]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF7458.cfxxe" [X]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Dopl�kov� sken -------
.
uLocal Page = c:\windows\SYSTEM32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: {76408C75-C11F-4AFC-9C77-C4289F0CC8DE} = 192.168.2.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
.
.
--------------------- ZAMKNUT� KL��E V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:62,11,cd,be,b2,6a,22,42,ea,70,7f,e6,62,fe,61,5a,d6,99,02,4c,7b,5b,10,
92,2d,74,16,a4,0d,c2,76,4c,8b,1f,b5,f3,2c,05,ae,6d,5c,10,4f,18,8d,f5,71,cd,\
"??"=hex:c3,26,06,7f,34,67,ca,e0,4f,9e,cb,24,ea,da,30,eb
[HKEY_USERS\S-1-5-21-3049775063-532791586-3059231688-1001\Software\SecuROM\License information*]
"datasecu"=hex:f7,df,3c,eb,4c,90,48,8d,54,d6,7d,50,fc,ff,cb,ae,74,af,b5,54,22,
eb,03,0b,28,23,58,ea,d6,7d,b1,16,0e,79,19,a8,f1,a6,b3,8d,22,7c,f9,b5,db,b4,\
"rkeysecu"=hex:a7,fd,be,5f,3a,22,f5,0a,8e,68,9a,f8,72,f3,90,8d
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Jin� spu�ten� procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
.
**************************************************************************
.
Celkov� �as: 2010-12-30 19:30:05 - po��ta� byl restartov�n
ComboFix-quarantined-files.txt 2010-12-30 18:30
ComboFix2.txt 2010-12-30 17:19
P�ed spu�t�n�m: Voln�ch bajt�: 18�125�516�800
Po spu�t�n�: Voln�ch bajt�: 17�792�950�272
- - End Of File - - CEF58C0C090F62BB19248BAF91F05BD6