ComboFix 12-01-03.04 - Deniska 04.01.2012 12:58:29.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3767.2215 [GMT 1:00]
Spuštěný z: c:\users\Deniska\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Deniska\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2507351934-888822584-2405633601-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2507351934-888822584-2405633601-1000UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ICQ6Toolbar
c:\program files (x86)\ICQ6Toolbar\config.xml
c:\program files (x86)\ICQ6Toolbar\Icons.bmp
c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe
c:\program files (x86)\ICQ6Toolbar\icq6Toolbar.ico
c:\program files (x86)\ICQ6Toolbar\ICQToolBar.dll
c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files (x86)\ICQ6Toolbar\logo_small.gif
c:\program files (x86)\ICQ6Toolbar\ServiceStarter.exe
c:\program files (x86)\ICQ6Toolbar\short.wav
c:\program files (x86)\ICQ6Toolbar\Version.txt
c:\program files (x86)\ICQ6Toolbar\voucher.bmp
c:\program files (x86)\ICQ6Toolbar\voucher2.bmp
c:\users\Deniska\AppData\Local\Facebook\Update
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\FacebookCrashHandler.exe
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\FacebookUpdate.exe
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\FacebookUpdateHelper.msi
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdate.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ar.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_bg.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_bn.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ca.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_cs.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_da.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_de.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_el.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_en-GB.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_en.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_es-419.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_es.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_et.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fa.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fi.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fil.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fr.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_gu.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hi.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hr.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hu.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_id.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_is.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_it.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_iw.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ja.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_kn.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ko.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lt.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lv.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ml.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_mr.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ms.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_nl.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_no.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_or.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pl.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-BR.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-PT.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ro.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ru.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sk.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sl.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sr.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sv.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ta.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_te.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_th.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_tr.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_uk.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ur.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_vi.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-CN.dll
c:\users\Deniska\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-TW.dll
c:\users\Deniska\AppData\Local\Facebook\Update\FacebookUpdate.exe
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\1525.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\313D.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\35A.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\4DF1.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\52D1.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\5A2.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\66ED.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\8349.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\92C5.exe
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\92C5.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\CC43.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\D7E7.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\EF5D.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\0C3D\F5F2.tmp
c:\users\Deniska\AppData\Roaming\Microsoft\6CFD
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2507351934-888822584-2405633601-1000Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2507351934-888822584-2405633601-1000UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_BFE
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-04 do 2012-01-04 )))))))))))))))))))))))))))))))
.
.
2012-01-04 12:04 . 2012-01-04 12:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-02 17:29 . 2012-01-02 17:29 -------- d-----w- C:\rsit
2012-01-02 17:29 . 2012-01-02 17:29 -------- d-----w- c:\program files\trend micro
2012-01-01 21:44 . 2012-01-01 21:44 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-01 21:44 . 2012-01-01 21:44 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-01 21:44 . 2012-01-01 21:44 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-01 21:44 . 2012-01-01 21:44 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-01 19:22 . 2012-01-01 19:22 286720 ----a-w- C:\swreg.exe
2011-12-31 02:36 . 2011-12-31 01:03 -------- d-----w- c:\windows\Microsoft Antimalware
2011-12-14 11:25 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 11:23 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 11:23 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-21 08:42 . 2011-05-31 04:06 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-07 04:16 . 2011-11-22 18:36 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{415102C8-AAB2-4415-BC00-741D1B532DA8}\mpengine.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-03_17.35.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 05:10 . 2012-01-04 11:40 39350 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2012-01-02 17:17 39350 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-09-16 23:17 . 2012-01-04 11:40 14702 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2507351934-888822584-2405633601-1000_UserData.bin
- 2010-09-16 23:17 . 2012-01-02 17:17 14702 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2507351934-888822584-2405633601-1000_UserData.bin
- 2009-02-28 05:01 . 2012-01-02 17:52 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-28 05:01 . 2012-01-04 12:05 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-28 05:01 . 2012-01-02 17:52 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-28 05:01 . 2012-01-04 12:05 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-01-03 17:57 . 2012-01-03 17:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012010320120104\index.dat
+ 2009-07-14 04:54 . 2012-01-04 12:05 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-02 17:52 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:46 . 2012-01-01 16:27 94640 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-07-14 04:46 . 2012-01-03 21:30 94640 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-09-16 23:19 . 2012-01-03 16:59 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-16 23:19 . 2012-01-04 11:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-16 23:19 . 2012-01-03 16:59 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-16 23:19 . 2012-01-04 11:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-02 17:11 . 2012-01-02 17:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-04 12:05 . 2012-01-04 12:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-02 17:11 . 2012-01-02 17:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-04 12:05 . 2012-01-04 12:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-19 18:44 . 2012-01-03 22:55 388274 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 05:01 . 2012-01-01 23:30 352504 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-04 12:04 352504 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2010-10-29 20:23 . 2012-01-01 19:33 353272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2507351934-888822584-2405633601-1000-8192.dat
+ 2010-10-29 20:23 . 2012-01-04 12:04 353272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2507351934-888822584-2405633601-1000-8192.dat
- 2012-01-01 19:46 . 2012-01-01 23:30 353272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2507351934-888822584-2405633601-1000-12288.dat
+ 2012-01-01 19:46 . 2012-01-03 22:58 353272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2507351934-888822584-2405633601-1000-12288.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192]
"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE" [2007-05-21 124512]
"Luxand Blink!"="c:\program files\Luxand\Blink!\LuxandBlinkTray.exe" [2010-10-18 7143224]
"Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2011-10-12 30192]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files (x86)\Acer\Acer VCM\AcerVCM.exe [2010-4-15 704032]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2011-10-12 30192]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-04-20 152064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/09/18 18:58];c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-03-13 10:58 146928]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-03-03 325200]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 ODDPwrSvc;Acer ODD Power Service;c:\program files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [2010-02-05 171040]
S2 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
"ODDPwr"="c:\program files\Acer\Optical Drive Power Management\ODDPwr.exe" [2010-02-05 222240]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-22 10081312]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-02-22 877600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-12 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-12 390680]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-12 410136]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-01-13 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2916584]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"combofix"="c:\combofix\CF28415.3XE" [2010-11-20 345088]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Deniska\AppData\Roaming\Mozilla\Firefox\Profiles\l02siibl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
Binary file temp00 matches
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
c:\windows\SysWOW64\RunDll32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
.
**************************************************************************
.
Celkový čas: 2012-01-04 13:10:17 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-04 12:10
ComboFix2.txt 2012-01-03 17:37
.
Před spuštěním: Volných bajtů: 12 351 741 952
Po spuštění: Volných bajtů: 12 114 575 360
.
- - End Of File - - 763DE90384557B50461D806578A518BA