ComboFix 12-12-14.01 - Céčko 15.12.2012 11:05:54.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3957.2834 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ICQ6Toolbar
c:\program files (x86)\ICQ6Toolbar\config.xml
c:\program files (x86)\ICQ6Toolbar\Icons.bmp
c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe
c:\program files (x86)\ICQ6Toolbar\icq6Toolbar.ico
c:\program files (x86)\ICQ6Toolbar\ICQToolBar.dll
c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files (x86)\ICQ6Toolbar\logo_small.gif
c:\program files (x86)\ICQ6Toolbar\ServiceStarter.exe
c:\program files (x86)\ICQ6Toolbar\short.wav
c:\program files (x86)\ICQ6Toolbar\Version.txt
c:\program files (x86)\ICQ6Toolbar\voucher.bmp
c:\program files (x86)\ICQ6Toolbar\voucher2.bmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-15 do 2012-12-15 )))))))))))))))))))))))))))))))
.
.
2012-12-14 21:14 . 2012-12-14 21:19 -------- d-----w- c:\program files (x86)\Opera
2012-12-14 20:00 . 2012-11-19 00:01 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{73477E51-F46B-4DCF-A9D5-C8F9132E88F1}\mpengine.dll
2012-12-14 17:52 . 2012-12-14 17:52 -------- d-----w- c:\program files\CCleaner
2012-12-13 02:00 . 2012-11-14 05:59 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-12-12 18:58 . 2012-12-13 18:21 -------- d-----w- c:\program files\trend micro
2012-12-12 16:05 . 2012-12-12 16:06 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-12-12 07:01 . 2012-11-09 05:45 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-12 07:01 . 2012-11-09 04:42 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-12-12 07:01 . 2012-11-22 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-12-12 07:01 . 2012-11-05 21:35 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-12 07:01 . 2012-11-05 20:41 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-12 07:01 . 2012-11-05 20:32 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-12 07:01 . 2012-11-05 20:32 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-12 07:01 . 2012-10-04 17:41 424960 ----a-w- c:\windows\system32\KernelBase.dll
2012-12-12 07:01 . 2012-10-04 17:41 1161216 ----a-w- c:\windows\system32\kernel32.dll
2012-12-12 07:01 . 2012-10-04 17:45 215040 ----a-w- c:\windows\system32\winsrv.dll
2012-12-12 07:01 . 2012-10-04 15:21 338432 ----a-w- c:\windows\system32\conhost.exe
2012-12-11 07:55 . 2012-08-22 18:12 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-12-11 07:55 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2012-12-11 07:55 . 2012-08-22 18:12 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-12-10 12:09 . 2012-12-10 12:09 -------- d-----w- c:\windows\system32\SPReview
2012-12-10 12:08 . 2012-12-10 12:08 -------- d-----w- c:\windows\system32\EventProviders
2012-12-10 12:06 . 2012-12-13 02:03 67413224 ----a-w- c:\windows\system32\MRT.exe
2012-12-10 12:01 . 2010-11-20 13:27 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
2012-12-10 12:00 . 2010-11-20 13:26 501248 ----a-w- c:\windows\system32\IPSECSVC.DLL
2012-12-10 11:59 . 2010-11-20 13:27 403968 ----a-w- c:\windows\system32\untfs.dll
2012-12-10 11:58 . 2010-11-20 13:27 47104 ----a-w- c:\windows\system32\wshbth.dll
2012-12-10 11:57 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2012-12-10 11:57 . 2010-11-20 12:21 189952 ----a-w- c:\program files (x86)\Windows Portable Devices\sqmapi.dll
2012-12-10 11:57 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2012-12-10 11:56 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2012-12-10 11:56 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll
2012-12-10 11:56 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll
2012-12-10 11:20 . 2012-12-10 11:20 -------- d-----w- c:\windows\SysWow64\Wat
2012-12-10 11:20 . 2012-12-10 11:20 -------- d-----w- c:\windows\system32\Wat
2012-12-10 02:17 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-12-10 02:03 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-12-10 02:03 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-12-10 02:03 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-12-10 02:03 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-12-10 02:03 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-12-09 03:05 . 2012-12-14 19:44 -------- d-----w- c:\windows\Panther
2012-12-09 03:04 . 2012-12-09 03:04 -------- d-----w- c:\windows\system32\oem
2012-12-09 03:03 . 2012-12-10 12:26 -------- d-----w- c:\windows\SysWow64\cs
2012-12-09 03:03 . 2012-12-10 12:26 -------- d-----w- c:\windows\SysWow64\wbem\cs-CZ
2012-12-09 03:03 . 2012-12-10 12:26 -------- d-----w- c:\windows\system32\cs
2012-12-09 03:03 . 2012-12-09 03:03 -------- d-----w- c:\windows\SysWow64\XPSViewer
2012-12-09 03:03 . 2012-12-09 03:03 -------- d-----w- c:\windows\SysWow64\drivers\cs-CZ
2012-12-09 03:03 . 2012-12-09 03:03 -------- d-----w- c:\windows\cs-CZ
2012-12-09 03:03 . 2012-12-10 12:26 -------- d-----w- c:\windows\system32\wbem\cs-CZ
2012-12-09 03:03 . 2012-12-10 12:26 -------- d-----w- c:\windows\system32\drivers\cs-CZ
2012-12-09 03:03 . 2012-12-09 03:03 -------- d-----w- c:\windows\system32\drivers\UMDF\cs-CZ
2012-12-09 03:01 . 2009-07-14 03:04 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
2012-12-09 02:21 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2012-12-09 02:21 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2012-12-09 02:21 . 2010-12-23 05:54 850944 ----a-w- c:\windows\SysWow64\sbe.dll
2012-12-09 02:21 . 2010-12-23 05:50 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
2012-12-09 02:21 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-12-09 02:21 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-12-09 02:21 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-12-09 02:21 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-12-09 02:21 . 2011-07-09 02:46 288768 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-12-09 02:21 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-12-09 02:21 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-12-09 02:21 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2012-12-09 02:21 . 2011-11-17 05:35 314880 ----a-w- c:\windows\SysWow64\webio.dll
2012-12-09 02:20 . 2012-06-06 06:06 1881600 ----a-w- c:\windows\system32\msxml3.dll
2012-12-09 02:20 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-12-09 02:20 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
2012-12-09 02:20 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2012-12-09 02:20 . 2010-06-26 03:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-12-09 02:20 . 2010-06-26 03:24 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2012-12-09 02:20 . 2012-08-30 18:03 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-12-09 02:20 . 2012-08-30 17:12 3968880 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-12-09 02:20 . 2012-08-30 17:12 3914096 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-12-09 02:18 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll
2012-12-09 02:17 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2012-12-09 01:56 . 2008-12-04 10:59 188416 ----a-w- c:\windows\system32\APOMgr64.DLL
2012-12-09 01:55 . 2009-10-09 19:52 831488 ----a-w- c:\windows\RtlExUpd.dll
2012-12-09 01:55 . 2012-12-09 01:55 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2012-12-09 01:49 . 2012-12-09 01:56 -------- d-----w- c:\program files (x86)\Realtek
2012-12-09 01:49 . 2009-08-20 23:05 239616 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2012-12-09 01:49 . 2009-07-22 17:24 97792 ----a-w- c:\windows\system32\RTNUninst64.dll
2012-12-09 01:49 . 2009-03-05 13:54 67584 ----a-w- c:\windows\system32\RtNicProp64.dll
2012-12-09 01:41 . 2012-12-09 01:41 -------- d-----w- c:\programdata\SupportSoft
2012-12-09 01:41 . 2012-12-09 01:41 -------- d-----w- c:\programdata\PCDr
2012-12-09 01:40 . 2012-12-09 01:40 -------- d-----w- c:\program files (x86)\Dell Support Center
2012-12-09 01:40 . 2012-12-09 01:40 -------- d-----w- c:\program files (x86)\Common Files\supportsoft
2012-12-09 01:40 . 2012-12-09 01:42 -------- d-----w- c:\programdata\Dell
2012-12-09 01:38 . 2012-12-09 01:38 -------- d-----w- c:\program files (x86)\NetWaiting
2012-12-09 01:34 . 2012-12-09 01:34 181760 ----a-w- c:\windows\system32\javaws.exe
2012-12-09 01:34 . 2012-12-09 01:34 165888 ----a-w- c:\windows\system32\javaw.exe
2012-12-09 01:34 . 2012-12-09 01:34 165888 ----a-w- c:\windows\system32\java.exe
2012-12-09 01:34 . 2012-12-09 01:34 455680 ----a-w- c:\windows\system32\deploytk.dll
2012-12-09 01:34 . 2012-12-09 01:34 -------- d-----w- c:\program files\Java
2012-12-09 01:27 . 2012-12-09 01:27 -------- d-----w- c:\program files\DellTPad
2012-12-09 01:27 . 2009-08-31 10:05 99328 ----a-w- c:\windows\system32\Vxdif.dll
2012-12-09 01:27 . 2006-11-02 07:04 1919968 ----a-w- c:\windows\system32\WdfCoInstaller01005.dll
2012-12-09 01:27 . 2009-09-16 20:47 267312 ----a-w- c:\windows\system32\drivers\Apfiltr.sys
2012-12-09 01:12 . 2012-12-09 01:12 -------- d-----w- C:\dell
2012-12-09 00:32 . 2012-12-09 00:32 -------- d-----w- c:\program files\Common Files\DESIGNER
2012-12-09 00:31 . 2012-12-09 00:31 -------- d-----w- c:\windows\PCHEALTH
2012-12-09 00:31 . 2012-12-09 00:31 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-12-09 00:28 . 2012-12-09 00:28 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-12-09 00:28 . 2012-12-09 00:28 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-12-09 00:28 . 2012-12-09 00:35 -------- d-----w- c:\programdata\Microsoft Help
2012-12-08 23:01 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-08 23:01 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-08 23:01 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-08 23:01 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-08 23:01 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-08 23:00 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-08 23:00 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-08 23:00 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-08 23:00 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-08 23:00 . 2012-12-08 23:00 -------- d-----w- c:\programdata\AVAST Software
2012-12-08 22:00 . 2012-12-08 22:00 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-12-08 22:00 . 2012-12-08 22:00 -------- d-----r- c:\program files (x86)\Skype
2012-12-08 22:00 . 2012-12-08 22:00 -------- d-----w- c:\programdata\Skype
2012-12-08 19:42 . 2012-12-09 01:56 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2012-12-08 19:42 . 2012-12-08 19:42 -------- d-----w- c:\programdata\ICQ
2012-12-08 18:51 . 2012-05-31 10:25 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-12-08 18:36 . 2012-12-08 18:36 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-08 18:36 . 2012-12-08 18:36 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-12-08 18:36 . 2012-12-08 18:36 -------- d-----w- c:\windows\SysWow64\Macromed
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-10 12:22 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-12-10 12:22 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-12-10 02:14 . 2012-12-10 02:14 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-12-10 02:14 . 2012-12-10 02:14 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2012-10-04 16:40 . 2012-12-12 07:00 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files (x86)\NetWaiting\netWaiting.exe" [2007-05-10 26144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="d:\programy\Avast\avastUI.exe" [2012-10-30 4297136]
"dellsupportcenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-12-10 1255736]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-10-09 92160]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 203264]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- d:\programy\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-09-16 357376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2012-12-09 171520]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-09 8158240]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - d:\programy\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - d:\programy\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\Céčko\AppData\Roaming\Mozilla\Firefox\Profiles\z5rsc801.default\
FF - ExtSQL: 2012-12-09 00:06;
wrc@avast.com; d:\programy\Avast\WebRep\FF
FF - ExtSQL: 2012-12-13 19:29; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\CĂ©Äko\AppData\Roaming\Mozilla\Firefox\Profiles\z5rsc801.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
.
------------------------ Jiné spuštené procesy ------------------------
.
d:\programy\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-12-15 11:18:49 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-12-15 10:18
ComboFix2.txt 2012-12-15 04:04
.
Před spuštěním: Volných bajtů: 29 256 957 952
Po spuštění: Volných bajtů: 28 813 361 152
.
- - End Of File - - 50783AACF6FB63CB9AE96B40569DB0F8