Re: CPU v klidu 100%
Napsal: 26 lis 2012 19:33
uf, už sem měl na mále, po té co combofix zkončil mi nešel spustin net a halzelo to hlašku, že něco z registru je připraveno k smazání iexplore asi, tak sem to restartoval a už to běželo jinak
zde je log
ComboFix 12-11-26.02 - Michal 26.11.2012 19:07:23.2.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3326.1522 [GMT 1:00]
Spuštěný z: c:\users\Michal\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Michal\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Assassin.LNK"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\ParetoLogic Registration3.job"
"c:\windows\tasks\ParetoLogic Update Version3.job"
"c:\windows\tasks\RegCure Pro.job"
.
file zipped: c:\users\Michal\AppData\Roaming\NetMeeting\ca32.exe
file zipped: c:\windows\system32\igfxupdate.exe
file zipped: c:\windows\system32\jureg.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Assassin.LNK
c:\users\Michal\AppData\Roaming\NetMeeting
c:\users\Michal\AppData\Roaming\NetMeeting\ca32.exe
c:\windows\system32\igfxupdate.exe
c:\windows\system32\jureg.exe
c:\windows\system32\update
c:\windows\tasks\Adobe Flash Player Updater.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\tasks\ParetoLogic Registration3.job
c:\windows\tasks\ParetoLogic Update Version3.job
c:\windows\tasks\RegCure Pro.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_SearchIndexer
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-26 do 2012-11-26 )))))))))))))))))))))))))))))))
.
.
2012-11-26 18:14 . 2012-11-26 18:17 -------- d-----w- c:\users\Michal\AppData\Local\temp
2012-11-26 18:14 . 2012-11-26 18:14 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-11-26 18:14 . 2012-11-26 18:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-26 17:30 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{87BFD32D-4EE1-4030-84EF-437FC8ED8A48}\mpengine.dll
2012-11-26 14:41 . 2012-11-26 14:41 -------- d-----w- c:\program files\trend micro
2012-11-26 14:41 . 2012-11-26 14:51 -------- d-----w- C:\rsit
2012-11-26 14:03 . 2012-11-26 14:03 -------- d-----w- c:\program files\SQUARE ENIX
2012-11-26 13:59 . 2012-11-26 16:01 -------- d-----w- c:\program files\Steam
2012-11-25 11:56 . 2012-11-26 14:01 -------- d-----w- c:\windows\system32\wbem\Logs
2012-11-25 10:53 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-24 17:49 . 2012-11-25 11:37 -------- d-----w- c:\users\Michal\.VirtualBox
2012-11-24 17:47 . 2012-11-26 13:58 -------- d-----w- c:\program files\Oracle
2012-11-23 14:39 . 2012-11-23 14:39 -------- d-----w- c:\windows\Downloaded Program Files
2012-11-22 21:25 . 2012-11-25 10:36 -------- d-----w- c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
2012-11-22 20:34 . 2012-11-22 20:51 -------- d-----w- c:\windows\Debug
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\users\Michal\AppData\Roaming\ParetoLogic
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\users\Michal\AppData\Roaming\DriverCure
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\program files\Common Files\ParetoLogic
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\programdata\ParetoLogic
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\program files\ParetoLogic
2012-11-22 19:18 . 2012-11-22 19:19 -------- d-----w- c:\users\Michal\{9ecffe79-742a-4793-8eab-c802973f1e18}
2012-11-22 19:18 . 2012-11-09 16:35 20335464 ----a-w- c:\windows\system32\nvoglv32.dll
2012-11-22 19:18 . 2012-11-09 16:35 1874280 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-11-22 19:18 . 2012-11-09 16:35 17559912 ----a-w- c:\windows\system32\nvcompiler.dll
2012-11-22 19:18 . 2012-11-09 16:35 9364840 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-11-22 19:18 . 2012-11-09 16:35 7818504 ----a-w- c:\windows\system32\nvcuda.dll
2012-11-22 19:18 . 2012-11-09 16:35 6149904 ----a-w- c:\windows\system32\nvopencl.dll
2012-11-22 19:18 . 2012-11-09 16:35 2606440 ----a-w- c:\windows\system32\nvcuvid.dll
2012-11-22 19:15 . 2012-11-22 19:15 -------- d-----w- c:\windows\cs
2012-11-22 19:14 . 2012-11-22 19:14 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-11-22 19:12 . 2012-11-22 19:13 -------- d-----w- c:\program files\Windows Live
2012-11-22 19:11 . 2012-11-22 19:11 -------- d-----w- c:\users\Michal\AppData\Local\Windows Live
2012-11-22 19:11 . 2012-11-22 19:11 -------- d-----w- c:\program files\Common Files\Windows Live
2012-11-22 19:10 . 2009-08-04 08:02 754688 ----a-w- c:\windows\system32\webservices.dll
2012-11-22 19:02 . 2012-11-22 20:54 410112 ----a-w- c:\windows\system32\taskhost.rs
2012-11-22 19:02 . 2012-11-22 20:54 270848 ----a-w- c:\windows\system32\SearchEngine.rs
2012-11-22 19:02 . 2012-11-22 19:36 371712 ----a-w- c:\windows\system32\SearchIndexer.dll
2012-11-22 16:06 . 2012-11-22 16:26 -------- d-----w- c:\users\Michal\AppData\Roaming\GlarySoft
2012-11-22 15:53 . 2012-11-22 15:53 -------- d-----w- c:\programdata\Iomatic
2012-11-22 14:54 . 2012-11-22 14:54 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2012-11-22 14:52 . 2012-11-22 20:30 -------- d-----w- c:\users\Michal\AppData\Roaming\PC Cleaners
2012-11-22 14:52 . 2012-11-22 14:51 4589880 ----a-w- c:\windows\uninst.exe
2012-11-22 14:52 . 2012-11-22 14:52 -------- d-----w- c:\users\Michal\AppData\Roaming\PCPro
2012-11-22 14:52 . 2012-11-22 14:52 -------- d-----w- c:\programdata\PC1Data
2012-11-22 14:30 . 2012-11-22 14:30 -------- d-----w- c:\windows\Sun
2012-11-20 18:32 . 2012-11-20 18:32 -------- d-----w- c:\users\Michal\AppData\Roaming\Theta
2012-11-19 11:47 . 2012-11-20 10:35 -------- d-sh--w- c:\users\Michal\Drivers
2012-11-19 07:27 . 2012-11-20 09:46 -------- d-----w- c:\program files\Ubisoft
2012-11-16 18:44 . 2012-09-25 16:19 75776 ----a-w- c:\windows\system32\synceng.dll
2012-11-16 18:44 . 2012-10-12 14:29 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-11-16 18:09 . 2012-11-16 18:09 2032 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2012-11-14 13:48 . 2012-11-22 20:30 -------- d-----w- c:\users\Michal\AppData\Roaming\Sony
2012-11-08 11:20 . 2012-11-08 11:20 -------- d-----w- c:\users\Michal\AppData\Local\ElevatedDiagnostics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-22 19:12 . 2009-08-18 10:24 19696 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-11-20 09:46 . 2009-05-28 11:09 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-11-20 09:46 . 2009-05-28 11:09 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-11-09 16:35 . 2012-10-10 20:14 889192 ----a-w- c:\windows\system32\nvdispgenco32.dll
2012-11-09 16:35 . 2011-09-29 18:49 1011048 ----a-w- c:\windows\system32\nvdispco32.dll
2012-11-09 16:35 . 2010-02-26 12:01 12541648 ----a-w- c:\windows\system32\nvwgf2um.dll
2012-11-09 16:35 . 2007-12-27 18:41 2496976 ----a-w- c:\windows\system32\nvapi.dll
2012-11-09 16:35 . 2007-12-27 18:41 15117136 ----a-w- c:\windows\system32\nvd3dum.dll
2012-11-09 12:19 . 2010-01-11 21:18 3984744 ----a-w- c:\windows\system32\nvcpl.dll
2012-11-09 12:19 . 2010-01-11 21:18 2869608 ----a-w- c:\windows\system32\nvsvc.dll
2012-11-09 12:19 . 2010-01-11 21:18 2557288 ----a-w- c:\windows\system32\nvsvcr.dll
2012-11-09 12:19 . 2010-01-11 21:18 108392 ----a-w- c:\windows\system32\nvmctray.dll
2012-11-09 12:19 . 2010-01-11 21:18 645480 ----a-w- c:\windows\system32\nvvsvc.exe
2012-11-09 12:19 . 2010-01-11 21:18 62312 ----a-w- c:\windows\system32\nvshext.dll
2012-10-11 07:49 . 2012-10-11 07:49 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 07:49 . 2012-10-11 07:49 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-28 06:51 . 2012-10-20 10:13 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4B3AAC6D-B85B-4839-8901-EC36BC58C43E}\gapaengine.dll
2012-09-28 06:51 . 2011-03-26 11:33 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-09-13 13:28 . 2012-10-10 19:01 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-03 19:38 . 2008-08-29 13:52 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2012-09-03 19:38 . 2008-08-29 13:52 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2012-08-30 20:03 . 2012-08-30 20:03 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-30 20:03 . 2010-10-24 20:25 99272 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-30 13:46 . 2012-08-30 13:46 65536 ----a-w- c:\windows\system32\frapsvid.dll
2012-08-29 11:27 . 2012-10-10 19:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-29 11:27 . 2012-10-10 19:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\users\Michal\{9ecffe79-742a-4793-8eab-c802973f1e18} ----
.
2012-11-22 19:18 . 2012-11-09 16:35 9364840 ----a-w- c:\users\Michal\{9ecffe79-742a-4793-8eab-c802973f1e18}\nvlddmkm.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 4702208]
"hpfsched"="c:\windows\hpfsched.exe" [2000-06-21 36864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: Interfaces\{32172FAA-7755-47CD-81D4-DEB6EDB72D70}: NameServer = 192.168.53.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-26 19:18
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3300)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
c:\windows\system32\spool\drivers\w32x86\hpzstatn.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\PANDORA.TV\PanService\PandoraService.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\iashost.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\ehome\ehmsas.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\ehome\ehsched.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehRecvr.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2012-11-26 19:22:29 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-26 18:22
ComboFix2.txt 2012-11-26 16:36
.
Před spuštěním: Volných bajtů: 249 092 464 640
Po spuštění: Volných bajtů: 249 126 879 232
.
- - End Of File - - B59560B4CE6EF4DBA9BE588FC475A191
Nahr nˇ probŘhlo ŁspŘçnŘ
zde je log
ComboFix 12-11-26.02 - Michal 26.11.2012 19:07:23.2.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3326.1522 [GMT 1:00]
Spuštěný z: c:\users\Michal\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Michal\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Assassin.LNK"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\ParetoLogic Registration3.job"
"c:\windows\tasks\ParetoLogic Update Version3.job"
"c:\windows\tasks\RegCure Pro.job"
.
file zipped: c:\users\Michal\AppData\Roaming\NetMeeting\ca32.exe
file zipped: c:\windows\system32\igfxupdate.exe
file zipped: c:\windows\system32\jureg.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Assassin.LNK
c:\users\Michal\AppData\Roaming\NetMeeting
c:\users\Michal\AppData\Roaming\NetMeeting\ca32.exe
c:\windows\system32\igfxupdate.exe
c:\windows\system32\jureg.exe
c:\windows\system32\update
c:\windows\tasks\Adobe Flash Player Updater.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\tasks\ParetoLogic Registration3.job
c:\windows\tasks\ParetoLogic Update Version3.job
c:\windows\tasks\RegCure Pro.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_SearchIndexer
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-26 do 2012-11-26 )))))))))))))))))))))))))))))))
.
.
2012-11-26 18:14 . 2012-11-26 18:17 -------- d-----w- c:\users\Michal\AppData\Local\temp
2012-11-26 18:14 . 2012-11-26 18:14 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-11-26 18:14 . 2012-11-26 18:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-26 17:30 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{87BFD32D-4EE1-4030-84EF-437FC8ED8A48}\mpengine.dll
2012-11-26 14:41 . 2012-11-26 14:41 -------- d-----w- c:\program files\trend micro
2012-11-26 14:41 . 2012-11-26 14:51 -------- d-----w- C:\rsit
2012-11-26 14:03 . 2012-11-26 14:03 -------- d-----w- c:\program files\SQUARE ENIX
2012-11-26 13:59 . 2012-11-26 16:01 -------- d-----w- c:\program files\Steam
2012-11-25 11:56 . 2012-11-26 14:01 -------- d-----w- c:\windows\system32\wbem\Logs
2012-11-25 10:53 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-24 17:49 . 2012-11-25 11:37 -------- d-----w- c:\users\Michal\.VirtualBox
2012-11-24 17:47 . 2012-11-26 13:58 -------- d-----w- c:\program files\Oracle
2012-11-23 14:39 . 2012-11-23 14:39 -------- d-----w- c:\windows\Downloaded Program Files
2012-11-22 21:25 . 2012-11-25 10:36 -------- d-----w- c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
2012-11-22 20:34 . 2012-11-22 20:51 -------- d-----w- c:\windows\Debug
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\users\Michal\AppData\Roaming\ParetoLogic
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\users\Michal\AppData\Roaming\DriverCure
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\program files\Common Files\ParetoLogic
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\programdata\ParetoLogic
2012-11-22 20:16 . 2012-11-22 20:16 -------- d-----w- c:\program files\ParetoLogic
2012-11-22 19:18 . 2012-11-22 19:19 -------- d-----w- c:\users\Michal\{9ecffe79-742a-4793-8eab-c802973f1e18}
2012-11-22 19:18 . 2012-11-09 16:35 20335464 ----a-w- c:\windows\system32\nvoglv32.dll
2012-11-22 19:18 . 2012-11-09 16:35 1874280 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-11-22 19:18 . 2012-11-09 16:35 17559912 ----a-w- c:\windows\system32\nvcompiler.dll
2012-11-22 19:18 . 2012-11-09 16:35 9364840 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-11-22 19:18 . 2012-11-09 16:35 7818504 ----a-w- c:\windows\system32\nvcuda.dll
2012-11-22 19:18 . 2012-11-09 16:35 6149904 ----a-w- c:\windows\system32\nvopencl.dll
2012-11-22 19:18 . 2012-11-09 16:35 2606440 ----a-w- c:\windows\system32\nvcuvid.dll
2012-11-22 19:15 . 2012-11-22 19:15 -------- d-----w- c:\windows\cs
2012-11-22 19:14 . 2012-11-22 19:14 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-11-22 19:12 . 2012-11-22 19:13 -------- d-----w- c:\program files\Windows Live
2012-11-22 19:11 . 2012-11-22 19:11 -------- d-----w- c:\users\Michal\AppData\Local\Windows Live
2012-11-22 19:11 . 2012-11-22 19:11 -------- d-----w- c:\program files\Common Files\Windows Live
2012-11-22 19:10 . 2009-08-04 08:02 754688 ----a-w- c:\windows\system32\webservices.dll
2012-11-22 19:02 . 2012-11-22 20:54 410112 ----a-w- c:\windows\system32\taskhost.rs
2012-11-22 19:02 . 2012-11-22 20:54 270848 ----a-w- c:\windows\system32\SearchEngine.rs
2012-11-22 19:02 . 2012-11-22 19:36 371712 ----a-w- c:\windows\system32\SearchIndexer.dll
2012-11-22 16:06 . 2012-11-22 16:26 -------- d-----w- c:\users\Michal\AppData\Roaming\GlarySoft
2012-11-22 15:53 . 2012-11-22 15:53 -------- d-----w- c:\programdata\Iomatic
2012-11-22 14:54 . 2012-11-22 14:54 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2012-11-22 14:52 . 2012-11-22 20:30 -------- d-----w- c:\users\Michal\AppData\Roaming\PC Cleaners
2012-11-22 14:52 . 2012-11-22 14:51 4589880 ----a-w- c:\windows\uninst.exe
2012-11-22 14:52 . 2012-11-22 14:52 -------- d-----w- c:\users\Michal\AppData\Roaming\PCPro
2012-11-22 14:52 . 2012-11-22 14:52 -------- d-----w- c:\programdata\PC1Data
2012-11-22 14:30 . 2012-11-22 14:30 -------- d-----w- c:\windows\Sun
2012-11-20 18:32 . 2012-11-20 18:32 -------- d-----w- c:\users\Michal\AppData\Roaming\Theta
2012-11-19 11:47 . 2012-11-20 10:35 -------- d-sh--w- c:\users\Michal\Drivers
2012-11-19 07:27 . 2012-11-20 09:46 -------- d-----w- c:\program files\Ubisoft
2012-11-16 18:44 . 2012-09-25 16:19 75776 ----a-w- c:\windows\system32\synceng.dll
2012-11-16 18:44 . 2012-10-12 14:29 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-11-16 18:09 . 2012-11-16 18:09 2032 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2012-11-14 13:48 . 2012-11-22 20:30 -------- d-----w- c:\users\Michal\AppData\Roaming\Sony
2012-11-08 11:20 . 2012-11-08 11:20 -------- d-----w- c:\users\Michal\AppData\Local\ElevatedDiagnostics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-22 19:12 . 2009-08-18 10:24 19696 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-11-20 09:46 . 2009-05-28 11:09 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-11-20 09:46 . 2009-05-28 11:09 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-11-09 16:35 . 2012-10-10 20:14 889192 ----a-w- c:\windows\system32\nvdispgenco32.dll
2012-11-09 16:35 . 2011-09-29 18:49 1011048 ----a-w- c:\windows\system32\nvdispco32.dll
2012-11-09 16:35 . 2010-02-26 12:01 12541648 ----a-w- c:\windows\system32\nvwgf2um.dll
2012-11-09 16:35 . 2007-12-27 18:41 2496976 ----a-w- c:\windows\system32\nvapi.dll
2012-11-09 16:35 . 2007-12-27 18:41 15117136 ----a-w- c:\windows\system32\nvd3dum.dll
2012-11-09 12:19 . 2010-01-11 21:18 3984744 ----a-w- c:\windows\system32\nvcpl.dll
2012-11-09 12:19 . 2010-01-11 21:18 2869608 ----a-w- c:\windows\system32\nvsvc.dll
2012-11-09 12:19 . 2010-01-11 21:18 2557288 ----a-w- c:\windows\system32\nvsvcr.dll
2012-11-09 12:19 . 2010-01-11 21:18 108392 ----a-w- c:\windows\system32\nvmctray.dll
2012-11-09 12:19 . 2010-01-11 21:18 645480 ----a-w- c:\windows\system32\nvvsvc.exe
2012-11-09 12:19 . 2010-01-11 21:18 62312 ----a-w- c:\windows\system32\nvshext.dll
2012-10-11 07:49 . 2012-10-11 07:49 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 07:49 . 2012-10-11 07:49 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-28 06:51 . 2012-10-20 10:13 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4B3AAC6D-B85B-4839-8901-EC36BC58C43E}\gapaengine.dll
2012-09-28 06:51 . 2011-03-26 11:33 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-09-13 13:28 . 2012-10-10 19:01 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-03 19:38 . 2008-08-29 13:52 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2012-09-03 19:38 . 2008-08-29 13:52 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2012-08-30 20:03 . 2012-08-30 20:03 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-30 20:03 . 2010-10-24 20:25 99272 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-30 13:46 . 2012-08-30 13:46 65536 ----a-w- c:\windows\system32\frapsvid.dll
2012-08-29 11:27 . 2012-10-10 19:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-29 11:27 . 2012-10-10 19:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\users\Michal\{9ecffe79-742a-4793-8eab-c802973f1e18} ----
.
2012-11-22 19:18 . 2012-11-09 16:35 9364840 ----a-w- c:\users\Michal\{9ecffe79-742a-4793-8eab-c802973f1e18}\nvlddmkm.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 4702208]
"hpfsched"="c:\windows\hpfsched.exe" [2000-06-21 36864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: Interfaces\{32172FAA-7755-47CD-81D4-DEB6EDB72D70}: NameServer = 192.168.53.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-26 19:18
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3300)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
c:\windows\system32\spool\drivers\w32x86\hpzstatn.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\PANDORA.TV\PanService\PandoraService.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\iashost.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\ehome\ehmsas.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\ehome\ehsched.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehRecvr.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2012-11-26 19:22:29 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-26 18:22
ComboFix2.txt 2012-11-26 16:36
.
Před spuštěním: Volných bajtů: 249 092 464 640
Po spuštění: Volných bajtů: 249 126 879 232
.
- - End Of File - - B59560B4CE6EF4DBA9BE588FC475A191
Nahr nˇ probŘhlo ŁspŘçnŘ