ComboFix 12-08-10.02 - Marcillon 12.08.2012 22:01:50.1.4 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.632 [GMT 2:00]
Spuštěný z: c:\users\Marcillon\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\Marcillon\AppData\Roaming\7za.exe
c:\users\Marcillon\AppData\Roaming\a.7z
c:\users\Marcillon\AppData\Roaming\Google\Update\1
c:\users\Marcillon\AppData\Roaming\Google\Update\1\SD\m.txt
c:\users\Marcillon\AppData\Roaming\Google\Update\1\SD\s.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-12 do 2012-08-12 )))))))))))))))))))))))))))))))
.
.
2012-08-12 20:05 . 2012-08-12 20:05 -------- d-----w- c:\users\Marcillon\AppData\Local\temp
2012-08-12 20:05 . 2012-08-12 20:05 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-08-12 20:05 . 2012-08-12 20:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-12 17:47 . 2012-08-12 17:47 -------- d-----w- c:\users\Marcillon\AppData\Roaming\Avira
2012-08-12 17:40 . 2012-07-18 16:05 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-08-12 17:40 . 2012-07-18 16:05 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-08-12 17:40 . 2012-07-18 16:05 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-08-12 17:40 . 2012-08-12 17:40 -------- d-----w- c:\programdata\Avira
2012-08-12 17:40 . 2012-08-12 17:40 -------- d-----w- c:\program files\Avira
2012-08-12 17:36 . 2012-08-12 17:36 -------- d-----w- c:\programdata\GFI Software
2012-08-11 21:11 . 2012-08-12 11:08 -------- d-----w- c:\program files\trend micro
2012-08-10 16:46 . 2012-08-11 18:41 -------- d-----w- c:\users\Marcillon\AppData\Local\PokerStars
2012-08-10 16:45 . 2012-08-10 16:50 -------- d-----w- c:\program files\PokerStars
2012-08-10 16:45 . 2012-08-11 20:32 -------- d-----w- c:\users\Marcillon\AppData\Roaming\Microgaming
2012-08-10 16:43 . 2012-08-10 16:43 -------- d-----w- c:\programdata\MGS
2012-08-10 16:43 . 2012-08-10 16:43 -------- d-----w- C:\Microgaming
2012-08-07 20:18 . 2012-08-07 20:18 -------- d-----w- c:\program files\Common Files\Steam
2012-08-06 12:44 . 2012-08-06 12:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-08-06 12:43 . 2012-08-06 12:43 -------- d-----w- c:\windows\PCHEALTH
2012-08-06 12:43 . 2012-08-06 12:43 -------- d-----w- c:\program files\Microsoft.NET
2012-08-06 12:43 . 2012-08-06 12:43 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-08-06 12:43 . 2012-08-06 12:43 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-08-06 12:43 . 2012-08-06 12:43 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-08-06 12:42 . 2012-08-06 12:42 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-08-06 12:42 . 2012-08-06 12:42 -------- d-----w- c:\users\Marcillon\AppData\Local\Microsoft Help
2012-08-06 12:41 . 2012-08-06 12:47 -------- d-----w- c:\programdata\Microsoft Help
2012-08-06 12:41 . 2012-08-06 12:41 -------- d-----r- C:\MSOCache
2012-08-05 15:49 . 2012-08-12 17:36 -------- d-----w- c:\program files\Ad-Aware Antivirus
2012-08-05 15:49 . 2012-08-05 15:49 -------- d-----w- c:\programdata\Lavasoft
2012-08-05 15:49 . 2012-08-05 15:49 -------- d-----w- c:\users\Marcillon\AppData\Local\Downloaded Installations
2012-08-05 15:49 . 2012-08-05 15:49 -------- d-----w- c:\users\Marcillon\AppData\Local\adawarebp
2012-08-05 15:48 . 2012-08-05 15:48 -------- d-----w- c:\program files\Toolbar Cleaner
2012-08-05 15:48 . 2012-08-05 15:48 -------- d-----w- c:\users\Marcillon\AppData\Roaming\Blekko
2012-08-05 15:48 . 2012-08-05 15:48 -------- d-----w- c:\program files\adawaretb
2012-08-05 15:48 . 2012-08-05 20:40 -------- d-----w- c:\users\Marcillon\AppData\Roaming\Ad-Aware Antivirus
2012-08-04 22:08 . 2012-08-04 22:13 -------- d-----w- C:\Reborn
2012-07-16 18:24 . 2012-05-15 09:28 2561344 ----a-w- c:\windows\system32\nvsvcr.dll
2012-07-16 18:23 . 2012-05-15 10:26 2524992 ----a-w- c:\windows\system32\nvcuvid.dll
2012-07-16 18:23 . 2012-05-15 10:26 2445120 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-07-16 18:23 . 2012-05-15 10:26 19607872 ----a-w- c:\windows\system32\nvoglv32.dll
2012-07-16 18:23 . 2012-05-15 10:26 11354944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-07-16 18:23 . 2012-05-15 10:26 5982528 ----a-w- c:\windows\system32\nvcuda.dll
2012-07-16 18:23 . 2012-05-15 10:26 17551680 ----a-w- c:\windows\system32\nvcompiler.dll
2012-07-16 17:58 . 2012-07-16 18:25 -------- d-----w- c:\program files\Diablo III
2012-07-16 17:58 . 2012-07-16 18:12 -------- d-----w- c:\programdata\Blizzard Entertainment
2012-07-16 17:58 . 2012-07-16 18:12 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2012-07-14 23:16 . 2012-07-14 23:16 -------- d-----w- c:\users\Marcillon\AppData\Roaming\NVIDIA
2012-07-14 23:14 . 2012-08-05 17:28 -------- d-----w- c:\program files\Worms Reloaded
2012-07-13 21:49 . 2012-07-13 21:58 -------- d-----w- c:\users\Marcillon\AppData\Roaming\EBookSys
2012-07-13 21:49 . 2012-07-13 21:49 -------- d-----w- c:\program files\E-Book Systems
2012-07-13 21:41 . 2012-07-13 21:41 -------- d-----w- c:\programdata\Premium
2012-07-13 21:41 . 2012-07-13 21:41 -------- d-----w- c:\programdata\InstallMate
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-03 12:20 . 2012-05-22 23:13 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-03 12:20 . 2012-05-22 23:13 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-23 00:23 . 2012-05-23 00:20 2829 ----a-w- c:\windows\War3Unin.pif
2012-05-23 00:23 . 2012-05-23 00:20 139264 ----a-w- c:\windows\War3Unin.exe
2012-05-22 23:44 . 2012-05-22 23:44 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-05-15 10:26 . 2012-05-23 00:13 883008 ----a-w- c:\windows\system32\nvgenco32.dll
2012-05-15 10:26 . 2012-05-23 00:13 61248 ----a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:26 . 2012-05-23 00:13 2368832 ----a-w- c:\windows\system32\nvapi.dll
2012-05-15 10:26 . 2012-05-23 00:13 1000768 ----a-w- c:\windows\system32\nvdispco32.dll
2012-05-15 10:26 . 2009-07-13 22:09 8105280 ----a-w- c:\windows\system32\nvwgf2um.dll
2012-05-15 10:26 . 2009-06-10 21:19 15322432 ----a-w- c:\windows\system32\nvd3dum.dll
2012-05-15 09:28 . 2012-05-23 00:14 645440 ----a-w- c:\windows\system32\nvvsvc.exe
2012-05-15 09:28 . 2012-05-23 00:14 62272 ----a-w- c:\windows\system32\nvshext.dll
2012-05-15 09:28 . 2012-05-23 00:14 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-15 09:28 . 2012-05-23 00:14 3931456 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-15 09:27 . 2012-05-23 00:14 2759488 ----a-w- c:\windows\system32\nvsvc.dll
2012-05-15 00:21 . 2012-05-15 00:21 423744 ----a-w- c:\windows\system32\nvStreaming.exe
2012-05-14 23:43 . 2012-05-22 23:26 6737808 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0D1D3B81-D4DB-4E0B-AADF-89774A8BBCBD}\mpengine.dll
2012-08-04 11:53 . 2012-05-27 19:21 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"GarenaMessenger"="c:\program files\Garena Plus\GarenaMessenger.exe" [2012-07-31 7123320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-07-18 348664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Antivirus]
c:\program files\Ad-Aware Antivirus\AdAwareLauncher --windows-run [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 12:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2012-04-11 09:54 3672384 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
2011-12-09 16:14 6835072 ----a-w- c:\program files\QIP 2010\qip.exe
.
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Plus\Room\safedrv.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R4 4game;4game;c:\program files\4game\4game\4GameService.exe [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - SSMDRV
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-22 12:20]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_1&u=___userid___
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 213.46.172.36 192.168.0.1
FF - ProfilePath - c:\users\Marcillon\AppData\Roaming\Mozilla\Firefox\Profiles\0fmekfxl.default\
FF - prefs.js: browser.search.selectedEngine - Blekko
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
MSConfigStartUp-Ad-Aware Browsing Protection - c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe
AddRemove-uTorrentControl2 Toolbar - c:\program files\uTorrentControl2\uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-08-12 22:06:49
ComboFix-quarantined-files.txt 2012-08-12 20:06
.
Před spuštěním: Volných bajtů: 142 686 904 320
Po spuštění: Volných bajtů: 142 605 697 024
.
- - End Of File - - 888FCAFBB2D1FA4A0C26722AFAE74DA3