Mam taky pocit ze to nefungovalo ale pre istotu prikladal log
ComboFix 13-01-17.03 - admin . 01. 2013 14:52:48.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.2046.783 [GMT 1:00]
Running from: c:\users\admin\Desktop\ComboFix.exe
Command switches used :: c:\users\admin\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\users\admin\AppData\Local\Temp\_uninst_.bat"
"c:\users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_.lnk"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\admin\AppData\Roaming\config.tcf
c:\users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_.lnk
c:\windows\My.ini
c:\windows\system32\BReWErS.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_80962822
.
.
((((((((((((((((((((((((( Files Created from 2012-12-17 to 2013-01-17 )))))))))))))))))))))))))))))))
.
.
2013-01-17 14:01 . 2013-01-17 14:05 -------- d-----w- c:\users\admin\AppData\Local\temp
2013-01-17 14:01 . 2013-01-17 14:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-17 13:21 . 2013-01-17 13:21 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{40CFFC86-1C46-49CF-8317-6BE401EA9521}\offreg.dll
2013-01-17 13:11 . 2013-01-17 13:11 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2013-01-16 15:56 . 2013-01-16 15:56 -------- d-----w- c:\users\admin\AppData\Local\ElevatedDiagnostics
2013-01-16 12:48 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{40CFFC86-1C46-49CF-8317-6BE401EA9521}\mpengine.dll
2013-01-15 19:02 . 2013-01-15 19:02 -------- d-----w- c:\programdata\Kaspersky Lab
2013-01-15 18:50 . 2013-01-15 18:50 -------- d-----w- c:\program files\Microsoft Silverlight
2013-01-15 18:47 . 2013-01-15 19:00 -------- dc----w- c:\users\admin\AppData\Local\MigWiz
2013-01-15 15:37 . 2013-01-15 15:37 -------- d-----w- c:\users\admin\AppData\Roaming\Malwarebytes
2013-01-15 15:37 . 2013-01-15 15:37 -------- d-----w- c:\programdata\Malwarebytes
2013-01-15 15:37 . 2013-01-15 15:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-15 15:37 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-15 15:03 . 2013-01-15 15:03 -------- d-----w- c:\program files\ERUNT
2013-01-11 15:15 . 2013-01-15 14:50 -------- d-----w- c:\programdata\Media Get LLC
2013-01-11 15:15 . 2013-01-15 14:50 -------- d-----w- c:\users\admin\AppData\Roaming\Media Get LLC
2013-01-11 15:15 . 2013-01-15 14:50 -------- d-----w- c:\users\admin\AppData\Local\MediaGet2
2013-01-11 15:15 . 2013-01-11 15:15 -------- d-----w- c:\users\admin\AppData\Local\Media Get LLC
2012-12-30 18:32 . 2012-12-30 18:32 -------- d-----w- c:\users\admin\AppData\Local\Programs
2012-12-23 20:46 . 2012-12-16 14:13 295424 ----a-w- c:\windows\system32\atmfd.dll
2012-12-23 20:46 . 2012-12-16 14:13 34304 ----a-w- c:\windows\system32\atmlib.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-15 16:09 . 2012-03-31 05:57 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-15 16:09 . 2011-05-18 05:34 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-22 02:56 . 2012-12-12 14:39 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-11-14 02:09 . 2012-12-12 20:17 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58 . 2012-12-12 20:17 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57 . 2012-12-12 20:17 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49 . 2012-12-12 20:17 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48 . 2012-12-12 20:17 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44 . 2012-12-12 20:17 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-09 04:42 . 2012-12-12 14:39 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-02 05:11 . 2012-12-12 14:34 376832 ----a-w- c:\windows\system32\dpnet.dll
2011-09-16 14:12 . 2011-12-27 15:13 3623592 ----a-w- c:\program files\Common Files\ApnToolbarInstaller.exe
2011-09-16 14:12 . 2011-12-27 15:13 143240 ----a-w- c:\program files\Common Files\ApnStub.exe
2012-12-17 16:59 . 2012-09-08 14:26 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b317125e-2f10-4388-bf1f-2c31c6cd89ed}"= "c:\program files\DigitalPowered\tbDigi.dll" [2009-10-01 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{b317125e-2f10-4388-bf1f-2c31c6cd89ed}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b317125e-2f10-4388-bf1f-2c31c6cd89ed}]
2009-10-01 16:29 2166296 ----a-w- c:\program files\DigitalPowered\tbDigi.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b317125e-2f10-4388-bf1f-2c31c6cd89ed}"= "c:\program files\DigitalPowered\tbDigi.dll" [2009-10-01 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{b317125e-2f10-4388-bf1f-2c31c6cd89ed}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-29 17148552]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-06-07 880528]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2012-12-01 3093624]
"Clownfish"="c:\program files\Clownfish\Clownfish.exe" [2012-11-30 1232632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 3080264]
.
c:\users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 apf003;apf003;c:\windows\system32\apf003.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Plus\Room\safedrv.sys [x]
R3 injectDLL;injectDLL;c:\users\admin\Desktop\Injector 32 bit\injectDLL.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files\BlueStacks\HD-Hypervisor-x86.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files\BlueStacks\HD-LogRotatorService.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 16:09]
.
2013-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-23 15:01]
.
2013-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-23 15:01]
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lid6k1ip.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\atieclxx.exe
c:\windows\System32\osk.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2013-01-17 15:11:48 - machine was rebooted
ComboFix-quarantined-files.txt 2013-01-17 14:11
ComboFix2.txt 2013-01-17 13:32
.
Pre-Run: 173 677 547 520 bytes free
Post-Run: 173 492 396 032 bytes free
.
- - End Of File - - 11916704F622CF515926BA7416F27755