Log CF:
-------
ComboFix 11-12-17.02 - Admin - 7 17.12.2011 19:05:50.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.6142.4795 [GMT 1:00]
Spuštěný z: c:\users\Admin - 7\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\winitn.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-17 do 2011-12-17 )))))))))))))))))))))))))))))))
.
.
2011-12-17 18:09 . 2011-12-17 18:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-17 16:09 . 2011-12-17 16:09 -------- d-----w- c:\windows\SysWow64\wbem\Performance
2011-12-16 19:04 . 2011-12-16 19:04 -------- d-----w- c:\users\Admin - 7\AppData\Local\ESET
2011-12-16 19:02 . 2011-12-16 19:02 -------- d-----w- c:\program files\ESET
2011-12-15 16:19 . 2011-12-15 16:19 -------- d-----w- c:\users\Admin - 7\AppData\Local\ElevatedDiagnostics
2011-12-14 19:47 . 2011-12-14 19:47 -------- d-----w- c:\users\Admin - 7\AppData\Local\CyberLink
2011-12-14 14:58 . 2011-12-14 14:58 -------- d-----w- c:\programdata\Malwarebytes
2011-12-14 10:34 . 2011-12-15 16:12 -------- d-----w- c:\program files\trend micro
2011-12-13 21:15 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-13 21:15 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-13 21:13 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-13 21:13 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-13 21:13 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-13 21:13 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-10 22:33 . 2011-12-10 22:38 -------- d-----w- c:\programdata\Creative
2011-12-10 22:30 . 2011-12-10 22:30 -------- d-----w- c:\program files\Creative
2011-12-10 22:30 . 2011-12-10 22:30 -------- d-----w- c:\program files (x86)\Common Files\Creative
2011-12-10 22:30 . 2011-12-10 22:30 -------- d-----w- c:\program files (x86)\Creative
2011-12-10 06:04 . 2011-12-10 06:04 -------- d-----w- c:\users\Admin - 7\AppData\Roaming\SUPERAntiSpyware.com
2011-12-10 06:04 . 2011-12-10 06:04 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-12-03 12:52 . 2011-12-03 13:41 -------- d-----w- c:\users\Admin - 7\AppData\Local\Activision
2011-12-03 03:54 . 2011-09-29 16:30 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2011-12-03 03:54 . 2011-09-29 16:30 646248 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2011-12-03 03:54 . 2011-11-09 13:21 31040 ----a-w- c:\windows\system32\nvhdap64.dll
2011-12-03 03:54 . 2011-11-09 13:21 187200 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2011-12-03 03:54 . 2011-11-09 13:21 1451840 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2011-12-03 03:10 . 2011-12-03 03:10 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-12-02 05:32 . 2011-09-08 15:40 508520 ----a-w- c:\windows\system32\drivers\Rtlh64.sys
2011-12-01 06:02 . 2011-12-02 07:49 -------- dc----w- c:\users\Admin - 7\AppData\Local\MigWiz
2011-11-30 15:58 . 2011-03-02 11:43 203264 ----a-w- c:\windows\system32\unrar.dll
2011-11-30 15:58 . 2011-11-23 18:00 86016 ----a-w- c:\windows\system32\ff_vfw.dll
2011-11-30 15:58 . 2011-11-30 15:58 -------- d-----w- c:\program files\K-Lite Codec Pack x64
2011-11-30 15:47 . 2011-11-30 15:47 -------- d-----w- c:\users\Admin - 7\AppData\Roaming\InstallShield Installation Information
2011-11-30 14:10 . 2011-03-23 15:46 18008 ----a-w- c:\windows\system32\AmUStor.dll
2011-11-30 14:10 . 2011-03-23 15:46 75352 ----a-w- c:\windows\system32\drivers\AmUStor.sys
2011-11-30 13:56 . 2009-11-02 16:42 25088 ----a-w- c:\windows\system32\drivers\gHidPnp.sys
2011-11-28 04:14 . 2009-11-02 16:47 14336 ----a-w- c:\windows\system32\drivers\gMouUsb.sys
2011-11-28 04:14 . 2010-11-04 14:16 143688 ----a-w- c:\windows\system32\drivers\MxEFUF64.sys
2011-11-27 02:36 . 2011-09-13 15:35 92160 ----a-w- c:\windows\system32\drivers\UBUMAPI.sys
2011-11-27 02:36 . 2011-09-13 15:35 24064 ----a-w- c:\windows\system32\drivers\UBSBM.sys
2011-11-27 02:36 . 2011-09-13 15:35 187392 ----a-w- c:\windows\system32\drivers\UB1394.sys
2011-11-27 02:36 . 2011-09-13 15:35 132608 ----a-w- c:\windows\system32\drivers\ubohci.sys
2011-11-27 02:36 . 2010-03-30 08:48 11832 ----a-w- c:\windows\system32\drivers\amdide64.sys
2011-11-27 00:22 . 2011-11-27 00:22 -------- d-----w- c:\programdata\Bluetooth
2011-11-27 00:18 . 2007-05-23 03:25 19728 ----a-w- c:\windows\system32\drivers\BtNetDrv.sys
2011-11-27 00:18 . 2007-05-11 02:12 38160 ----a-w- c:\windows\system32\drivers\blueletaudio.sys
2011-11-27 00:18 . 2007-03-05 04:48 37648 ----a-w- c:\windows\system32\drivers\BlueletSCOAudio.sys
2011-11-27 00:18 . 2007-03-05 04:44 23184 ----a-w- c:\windows\system32\drivers\VHIDMini.sys
2011-11-27 00:18 . 2007-03-05 04:42 49680 ----a-w- c:\windows\system32\drivers\BTHidMgr.sys
2011-11-27 00:18 . 2007-03-05 04:41 24976 ----a-w- c:\windows\system32\drivers\VBTEnum.sys
2011-11-27 00:18 . 2007-03-05 04:39 63248 ----a-w- c:\windows\system32\drivers\VcommMgr.sys
2011-11-27 00:18 . 2007-03-05 04:38 47120 ----a-w- c:\windows\system32\drivers\VComm.sys
2011-11-27 00:18 . 2006-10-08 23:29 32832 ----a-w- c:\windows\system32\drivers\BTNetFilter.sys
2011-11-27 00:18 . 2011-11-27 00:18 -------- d-----w- c:\program files (x86)\IVT Corporation
2011-11-26 23:53 . 2011-12-17 18:10 -------- d-----w- c:\programdata\NVIDIA
2011-11-26 23:53 . 2011-12-05 05:54 -------- d-----w- c:\users\UpdatusUser
2011-11-26 23:53 . 2011-11-26 23:54 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2011-11-26 23:53 . 2011-10-15 08:53 837952 ----a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-11-26 23:53 . 2011-10-15 08:53 5067584 ----a-w- c:\windows\system32\nvsvc64.dll
2011-11-26 23:53 . 2011-10-15 08:53 3074368 ----a-w- c:\windows\system32\nvsvcr.dll
2011-11-26 23:53 . 2011-10-15 08:53 222528 ----a-w- c:\windows\system32\nvmctray.dll
2011-11-26 23:53 . 2011-10-15 08:53 1640768 ----a-w- c:\windows\system32\nvvsvc.exe
2011-11-26 23:53 . 2011-10-15 08:53 137536 ----a-w- c:\windows\system32\nvshext.dll
2011-11-26 23:53 . 2011-10-15 08:53 10406208 ----a-w- c:\windows\system32\nvcpl.dll
2011-11-26 23:53 . 2011-11-26 23:53 -------- d-----w- c:\programdata\NVIDIA Corporation
2011-11-24 02:51 . 2011-11-26 01:54 -------- d-----w- c:\programdata\Futuremark
2011-11-23 22:19 . 2011-11-23 22:19 -------- d-----w- c:\users\Admin - 7\AppData\Local\Futuremark_Corporation
2011-11-23 22:13 . 2011-11-23 22:13 -------- d-----w- c:\users\Admin - 7\AppData\Local\IsolatedStorage
2011-11-23 21:58 . 2011-11-23 22:01 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2011-11-23 21:56 . 2011-11-23 21:56 -------- d-----w- c:\users\Admin - 7\AppData\Roaming\InstallShield
2011-11-23 21:55 . 2011-11-23 21:55 -------- d-----w- c:\program files (x86)\Futuremark
2011-11-21 21:15 . 2011-11-21 21:15 -------- d-----w- c:\users\Admin - 7\AppData\Local\Innovative Solutions
2011-11-21 21:15 . 2011-11-21 21:15 -------- d-----w- c:\programdata\Innovative Solutions
2011-11-21 05:52 . 2011-11-21 05:52 25640 ----a-w- c:\windows\etdrv.sys
2011-11-21 05:51 . 2011-11-21 05:51 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-20 00:42 . 2008-10-15 05:22 519000 ----a-w- c:\windows\system32\d3dx10_40.dll
2011-11-19 21:54 . 2011-11-19 21:54 -------- d-----w- c:\programdata\InstallShield
2011-11-19 21:38 . 2011-11-19 21:38 -------- d-----w- c:\programdata\AmUStor
2011-11-19 21:35 . 2011-11-19 21:55 -------- d-----w- c:\program files (x86)\Mobile Partner
2011-11-19 20:29 . 2011-11-21 21:53 -------- d-----w- c:\users\Admin - 7\AppData\Local\eSupport.com
2011-11-19 20:29 . 2011-11-19 20:29 21712 ----a-w- c:\windows\SysWow64\drivers\DrvAgent64.SYS
2011-11-17 18:24 . 2011-11-19 03:20 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 22:29 . 2011-09-04 23:33 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2011-12-10 22:29 . 2011-09-04 23:33 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-12-10 22:29 . 2011-09-04 23:33 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2011-12-10 22:29 . 2011-09-04 23:33 109144 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-11-22 18:54 . 2011-09-05 22:13 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-21 16:25 . 2011-09-06 03:23 25640 ----a-w- c:\windows\gdrv.sys
2011-11-11 19:14 . 2011-11-11 19:14 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2011-11-04 15:50 . 2011-03-28 17:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-10-28 10:38 . 2011-10-28 10:38 34032 ----a-w- c:\windows\system32\drivers\seehcri.sys
2011-10-27 06:06 . 2011-10-26 11:21 90112 ----a-w- c:\windows\SysWow64\agsaami.dll
2011-10-27 06:06 . 2011-10-26 11:21 610304 ----a-w- c:\windows\SysWow64\agsaamg.dll
2011-10-27 06:06 . 2011-10-26 11:21 372736 ----a-w- c:\windows\SysWow64\agsaamc.dll
2011-10-27 06:06 . 2011-10-26 11:21 2535424 ----a-w- c:\windows\SysWow64\agsaamj.dll
2011-10-26 11:21 . 2011-10-26 11:21 53760 ----a-w- c:\windows\system\ppacklib.dll
2011-10-20 14:05 . 2011-11-02 02:24 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-10-20 14:04 . 2011-11-04 14:57 35648 ----a-w- c:\windows\system32\uxtuneup.dll
2011-10-20 14:04 . 2011-11-04 14:57 28992 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-10-20 14:04 . 2011-11-02 02:24 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-10-20 14:04 . 2011-11-02 02:24 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-10-14 23:54 . 2011-10-14 23:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2011-10-07 16:48 . 2011-10-07 16:48 93200 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-10-07 16:47 . 2011-10-07 16:47 574216 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 16:47 . 2011-10-07 16:47 43248 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 16:47 . 2011-10-07 16:47 16528 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 16:47 . 2011-10-07 16:47 41200 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-07 16:47 . 2011-10-07 16:47 300200 ----a-w- c:\windows\SysWow64\guard32.dll
2011-10-07 16:47 . 2011-10-07 16:47 388280 ----a-w- c:\windows\system32\guard64.dll
2011-10-03 03:06 . 2011-09-10 05:12 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-29 16:30 . 2011-09-06 23:33 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2011-09-29 16:29 . 2011-11-11 13:55 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-11-12 16:55 1451336 ----a-w- c:\program files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-11-12 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"DAEMON Tools Pro Agent"="e:\počitačové programy\Windows-7\Daemon Profesional\DTAgent.exe" [2011-03-17 842048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files (x86)\AVG - Link Scanner\avgtray.exe" [2011-12-03 2415456]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2011-11-12 218464]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-07-07 24576]
"Adobe Reader Speed Launcher"="e:\počitačové programy\Windows-7\Adobe Reader-CZ\Reader\Reader_sl.exe" [2011-09-07 37296]
.
c:\users\Admin - 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\
Tapety 2.12.lnk - e:\počitačové programy\Windows-7\Menič Tapet\Tapety.exe [2004-10-17 211456]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AODDriver;AODDriver;c:\program files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-09-04 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-09-04 79360]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2011-11-21 25640]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-21 30528]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 scramby_out;Scramby Output;c:\windows\system32\drivers\scramby_out.sys [x]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 vcd10bus;Virtual CD v10 Bus Enumerator;c:\windows\system32\DRIVERS\vcd10bus.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 Active@ Disk Monitor;Active@ Disk Monitor;e:\počitačové programy\Windows-7\Manager Hardisku\DiskMonitorService.exe [2011-06-16 1465016]
R4 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;e:\počitačové programy\Windows-7\Power DVD - 2011\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-08-24 83240]
R4 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;e:\počitačové programy\Windows-7\Power DVD - 2011\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-08-26 75048]
R4 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;e:\počitačové programy\Windows-7\Power DVD - 2011\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [2011-08-26 292136]
R4 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-03-01 130976]
R4 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys [x]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S0 MxEFUF;Matrox Extio Upper Function Filter;c:\windows\system32\DRIVERS\MxEFUF64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [x]
S1 SASDIFSV;SASDIFSV;e:\počitačové programy\Windows-7\Super Antispyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;e:\počitačové programy\Windows-7\Super Antispyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;e:\počitačové programy\Windows-7\Super Antispyware\SASCORE64.EXE [2011-08-11 140672]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2011/10/17 03:10];e:\počitačové programy\Windows-7\Power DVD - 2011\PowerDVD11\Common\NavFilter\000.fcl [2011-09-01 20:51 148976]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG - Link Scanner\avgwdsvc.exe [2011-08-02 192776]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
S2 ntk_PowerDVD;ntk_PowerDVD;e:\počitačové programy\Windows-7\Power DVD - 2011\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-08-24 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;e:\počitačové programy\Windows-7\TuneUP Utilities-2012\TuneUpUtilitiesService64.exe [2011-10-20 2072896]
S2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\DRIVERS\ubsbm.sys [x]
S2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\DRIVERS\ubumapi.sys [x]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-11-12 246624]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\Drivers\gHidPnp.Sys [x]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\DRIVERS\gMouUsb.sys [x]
S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;e:\počitačové programy\Windows-7\TuneUP Utilities-2012\TuneUpUtilitiesDriver64.sys [2011-10-20 11856]
S3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\DRIVERS\ubohci.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
S3 vwmfbus;Vertex Wireless Composite Device driver (WDM);c:\windows\system32\DRIVERS\vwmfbus.sys [x]
S3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfdiag.sys [x]
S3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;c:\windows\system32\DRIVERS\vwmfmdfl.sys [x]
S3 vwmfmdm;Vertex Wireless CDC Modem Driver;c:\windows\system32\DRIVERS\vwmfmdm.sys [x]
S3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);c:\windows\system32\DRIVERS\vwmfserd.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="e:\počitačové programy\Windows-7\Comodo Firewal\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 9264456]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 4035152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.cz/
IE: E&xportovať do programu Microsoft Excel - e:\poitao~2\WINDOW~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz
Trusted Zone: mojebanka.cz
TCP: Interfaces\{7B5352CA-DA4F-41A8-BD71-03949963594E}: NameServer = 8.26.56.26,156.154.70.22
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Admin - 7\AppData\Roaming\Mozilla\Firefox\Profiles\13f15940.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B4ddd82a3-5d19-40ef-b0ab-a33e59bb2d6a%7D&mid=de43d152034147d1804ad1569633a338-9f3c4ad8e9defb3e5bec721f747bc854b75de8d1&ds=AVG&v=9.0.0.22&lang=cs&pr=fr&d=2011-11-12%2017%3A55%3A42&sap=ku&q=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-connections-per-server - 8
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\e:\počitačové programy\Windows-7\Power DVD - 2011\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
e:\poc:\Program Files (x86)\AVG - Link Scanner\avgtray.exe
.
**************************************************************************
.
Celkový čas: 2011-12-17 19:13:29 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-17 18:13
.
Před spuštěním: Volných bajtů: 37 482 823 680
Po spuštění: Volných bajtů: 36 930 125 824
.
- - End Of File - - 8B2ED4E46D6432B3C7DD1C690943E70E