- 2009-07-13 23:27 . 2009-07-14 01:14 2175488 c:\windows\AppPatch\AcGenral.dll
+ 2011-05-15 23:33 . 2010-11-20 12:18 2175488 c:\windows\AppPatch\AcGenral.dll
+ 2011-05-15 23:32 . 2010-11-20 12:08 12625408 c:\windows\SysWOW64\wmploc.DLL
- 2010-10-15 16:04 . 2010-09-01 04:23 12625408 c:\windows\SysWOW64\wmploc.DLL
+ 2011-05-15 23:34 . 2010-11-20 12:21 11410432 c:\windows\SysWOW64\wmp.dll
+ 2011-05-15 23:34 . 2010-11-20 12:21 12872192 c:\windows\SysWOW64\shell32.dll
+ 2011-05-15 23:32 . 2010-11-20 13:16 12625920 c:\windows\system32\wmploc.DLL
- 2010-10-15 16:04 . 2010-09-01 05:12 12625920 c:\windows\system32\wmploc.DLL
+ 2011-05-15 23:34 . 2010-11-20 13:27 14633472 c:\windows\system32\wmp.dll
+ 2009-07-14 02:34 . 2011-05-16 21:06 10543104 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2011-05-15 23:35 . 2010-11-20 13:27 14174208 c:\windows\system32\shell32.dll
+ 2011-05-15 23:33 . 2010-11-20 13:26 10085888 c:\windows\system32\migwiz\wet.dll
- 2009-07-13 23:33 . 2009-07-14 01:41 10085888 c:\windows\system32\migwiz\wet.dll
+ 2011-05-16 21:06 . 2011-05-16 21:06 10543104 c:\windows\ERDNT\subs\SCHEMA.DAT
+ 2011-05-16 20:58 . 2011-05-16 20:58 10543104 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
- 2009-07-14 00:47 . 2009-07-14 01:39 15697920 c:\windows\ehome\CreateDisc\SBEServer.exe
+ 2011-05-15 23:35 . 2010-11-20 13:25 15697920 c:\windows\ehome\CreateDisc\SBEServer.exe
+ 2011-05-16 20:23 . 2011-05-16 20:23 10617344 c:\windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll
+ 2011-05-16 20:25 . 2011-05-16 20:25 17379328 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\6c352ff9e3603b0e69d969ff7e7632f5\System.Windows.Forms.ni.dll
+ 2011-05-16 20:24 . 2011-05-16 20:24 15249408 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\ea5a0e7af3956d40caeffaab3bb8b753\System.Web.ni.dll
+ 2011-05-16 20:33 . 2011-05-16 20:33 23913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\ac74a0642981011a441823a762bfb3d8\System.ServiceModel.ni.dll
+ 2011-05-16 20:24 . 2011-05-16 20:24 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\d42a48a3e73b472a80d0d44038af89b0\System.Design.ni.dll
+ 2011-05-16 20:28 . 2011-05-16 20:28 19195392 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\09ca6fe45ec9d8c535413b0dfa7d2075\PresentationFramework.ni.dll
+ 2011-05-16 20:27 . 2011-05-16 20:27 16540160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\e097881a6e1956a4c3f6b8dbb81cb4ee\PresentationCore.ni.dll
+ 2011-05-16 20:23 . 2011-05-16 20:23 15568384 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll
+ 2011-05-16 20:26 . 2011-05-16 20:26 25470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\d1dc67c666bc15291be843bd67cd2a2e\ehshell.ni.dll
+ 2011-05-16 20:30 . 2011-05-16 20:30 12432896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
+ 2011-05-16 20:30 . 2011-05-16 20:30 11819520 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\da5da08245467818759aa44c4eb948e1\System.Web.ni.dll
+ 2011-05-16 20:32 . 2011-05-16 20:32 17478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e2642bff810609f64343e53dddb6b59c\System.ServiceModel.ni.dll
+ 2011-05-16 20:30 . 2011-05-16 20:30 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\52873358b397c328168f0a5be7f3b9ae\System.Design.ni.dll
+ 2011-05-16 20:31 . 2011-05-16 20:31 14339072 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bfaf8f86e69928fb2f67987c0203f603\PresentationFramework.ni.dll
+ 2011-05-16 20:31 . 2011-05-16 20:31 12234752 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\2ad23de8284d4594aa658dfb5e667d97\PresentationCore.ni.dll
+ 2011-05-16 20:29 . 2011-05-16 20:29 11490304 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2011-03-09 247728]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-05 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-09-08 249856]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 MADFUXPONENT;Service for M-Audio Xponent DFU;c:\windows\system32\DRIVERS\MAudioXponent_DFU.sys [x]
R3 MAUSBXPONENT;Service for M-Audio Xponent;c:\windows\system32\DRIVERS\MAudioXponent.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\nmwcdcx64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-07 79872]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592]
S2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2009-02-03 427192]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF28610.cfxxe" [X]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-22 7833120]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-05-22 1833504]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: {5995F79E-E50D-449C-B675-E54BF4CD78C7} = 192.168.0.1
DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://vpn.mze.cz/CACHE/stc/3/binaries/vpnweb.cab
DPF: {D67DB088-70B4-4006-B052-57F614FD3AA8} - hxxp://
www.vguard.net/myasp/chtIEx.cab
FF - ProfilePath - c:\users\zarofka\AppData\Roaming\Mozilla\Firefox\Profiles\3mpm1ogv.default\
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Celkový čas: 2011-05-16 23:16:03 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-16 21:16
ComboFix2.txt 2011-05-15 22:55
.
Před spuštěním: Volných bajtů: 114 453 483 520
Po spuštění: Volných bajtů: 114 119 798 784
.
- - End Of File - - D393C738DB1878DC89DD4295EE3CEF70
Toto by mělo být vše...
