tady to je
ComboFix 13-01-22.01 - Karel 23.01.2013 21:58:40.3.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2564 [GMT 1:00]
Spuštěný z: c:\users\Karel\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Karel\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files (x86)\TorrentMan\tbTorr.dll"
"c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk"
"c:\windows\Tasks\Adobe Flash Player Updater.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\AVGTemp
c:\avgtemp\reset_access_avg2013_en\7za.exe
c:\avgtemp\reset_access_avg2013_en\info.bat
c:\avgtemp\reset_access_avg2013_en\permavg.7z
c:\avgtemp\reset_access_avg2013_en\readme.txt
c:\avgtemp\reset_access_avg2013_en\reset_access.bat
c:\avgtemp\reset_access_avg2013_en\subinacl.exe
C:\found.000
c:\found.000\dir0000.chk\software
c:\found.000\dir0000.chk\system
c:\found.000\dir0001.chk\UsrClass.dat
c:\found.000\file0000.chk
c:\found.000\file0001.chk
c:\programdata\MFAData
c:\programdata\MFAData\mfaurlconf.ini
c:\programdata\MFAData\mkt\dtc\cz\toolbar.png
c:\programdata\MFAData\mkt\dtc\cz\ToolbarOfferScreen.html
c:\programdata\MFAData\mkt\dtc\res\offer.css
c:\programdata\MFAData\msistorg.dat
c:\programdata\MFAData\msistorg.dat.bkp
c:\programdata\MFAData\pack\AntiRka.cab
c:\programdata\MFAData\pack\Antivira.cab
c:\programdata\MFAData\pack\avg13infoavi.ctf
c:\programdata\MFAData\pack\avg13infooi.ctf
c:\programdata\MFAData\pack\avg13infowin.ctf
c:\programdata\MFAData\pack\avgcom_dtc.mdf
c:\programdata\MFAData\pack\Avgx64.msi
c:\programdata\MFAData\pack\AVIsa.cab
c:\programdata\MFAData\pack\base2a.cab
c:\programdata\MFAData\pack\basea.cab
c:\programdata\MFAData\pack\bins\f13avga2890gw.bin
c:\programdata\MFAData\pack\bins\foi13default_dtc20xl.bin
c:\programdata\MFAData\pack\bins\foi13default_lic8pu.bin
c:\programdata\MFAData\pack\bins\foi13default_mps14ca.bin
c:\programdata\MFAData\pack\bins\poi13avgcom_dtc20um.bin
c:\programdata\MFAData\pack\bins\poi13avgcom_lic8gv.bin
c:\programdata\MFAData\pack\bins\w13antirka2890px.bin
c:\programdata\MFAData\pack\bins\w13antispma2890wj.bin
c:\programdata\MFAData\pack\bins\w13antivira2890ci.bin
c:\programdata\MFAData\pack\bins\w13aspamdba2890lh.bin
c:\programdata\MFAData\pack\bins\w13avga2890hg.bin
c:\programdata\MFAData\pack\bins\w13avisa2890ij.bin
c:\programdata\MFAData\pack\bins\w13basa2890xv.bin
c:\programdata\MFAData\pack\bins\w13base2a2890ih.bin
c:\programdata\MFAData\pack\bins\w13corea2639co.bin
c:\programdata\MFAData\pack\bins\w13emailsa2890io.bin
c:\programdata\MFAData\pack\bins\w13fwa2890zm.bin
c:\programdata\MFAData\pack\bins\w13guia2890ko.bin
c:\programdata\MFAData\pack\bins\w13idpa2890kx.bin
c:\programdata\MFAData\pack\bins\w13ifwa2890qc.bin
c:\programdata\MFAData\pack\bins\w13lng_cza2890qv.bin
c:\programdata\MFAData\pack\bins\w13lng_usa2890sk.bin
c:\programdata\MFAData\pack\bins\w13rdsta2890ul.bin
c:\programdata\MFAData\pack\bins\w13rdstx2890mz.bin
c:\programdata\MFAData\pack\bins\w13resshlda2890ub.bin
c:\programdata\MFAData\pack\bins\w13srchsrfa2890ao.bin
c:\programdata\MFAData\pack\bins\w13sshttpba2890rf.bin
c:\programdata\MFAData\pack\bins\w13tdidrva2890ok.bin
c:\programdata\MFAData\pack\bins\w13tuneupa2890et.bin
c:\programdata\MFAData\pack\bins\w13update2a2890zz.bin
c:\programdata\MFAData\pack\bins\w13updatea2890jb.bin
c:\programdata\MFAData\pack\bins\w13xpla2890bi.bin
c:\programdata\MFAData\pack\COREa.cab
c:\programdata\MFAData\pack\COREx64.msi
c:\programdata\MFAData\pack\crt_x64.msi
c:\programdata\MFAData\pack\Emailsa.cab
c:\programdata\MFAData\pack\GUIa.cab
c:\programdata\MFAData\pack\IDPa.cab
c:\programdata\MFAData\pack\lic.mdf
c:\programdata\MFAData\pack\lng_cza.cab
c:\programdata\MFAData\pack\lng_usa.cab
c:\programdata\MFAData\pack\ResShlda.cab
c:\programdata\MFAData\pack\SrchSrfa.cab
c:\programdata\MFAData\pack\SSHttpBa.cab
c:\programdata\MFAData\pack\TDIDrva.cab
c:\programdata\MFAData\pack\TuneUpa.cab
c:\programdata\MFAData\pack\Update2a.cab
c:\programdata\MFAData\pack\Updatea.cab
c:\programdata\MFAData\pack\vc_red.cab
c:\programdata\MFAData\pack\vc_red.msi
c:\programdata\MFAData\pack\xpla.cab
c:\programdata\MFAData\public_installation_log.xml
c:\programdata\MFAData\survey\cancel.htm
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
c:\users\Karel\AppData\Local\Avg2013
c:\users\Karel\AppData\Local\MFAData
c:\users\Karel\AppData\Local\MFAData\logs\mfa-20130122-191255.log
c:\users\Karel\AppData\Local\MFAData\logs\mfa-20130122-191653.log
c:\users\Karel\AppData\Local\MFAData\logs\msi-20130122-191255.log
c:\users\Karel\AppData\Local\MFAData\logs\msi-20130122-191653.log
c:\users\Karel\AppData\Local\MFAData\logs\r86-20130122-191508.log
c:\users\Karel\AppData\Local\MFAData\logs\r86-20130122-191731.log
c:\windows\Tasks\Adobe Flash Player Updater.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-23 do 2013-01-23 )))))))))))))))))))))))))))))))
.
.
2013-01-23 21:05 . 2013-01-23 21:05 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-23 21:05 . 2013-01-23 21:05 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-01-23 21:05 . 2013-01-23 21:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-23 10:53 . 2013-01-23 10:53 -------- d-----w- c:\program files (x86)\yWorks
2013-01-23 10:48 . 2013-01-23 10:48 -------- d-----w- c:\users\Karel\AppData\Roaming\yWorks
2013-01-22 19:23 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-01-22 19:23 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-01-22 19:23 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-01-22 19:23 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-01-22 19:23 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-01-22 19:23 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-01-22 19:23 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2013-01-22 19:22 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2013-01-22 19:22 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2013-01-22 19:22 . 2013-01-22 19:22 -------- d-----w- c:\programdata\AVAST Software
2013-01-22 19:22 . 2013-01-22 19:22 -------- d-----w- c:\program files\AVAST Software
2013-01-22 18:33 . 2013-01-22 18:33 -------- d--h--w- c:\programdata\Common Files
2013-01-22 16:35 . 2013-01-22 16:35 -------- d-----w- c:\users\Karel\AppData\Roaming\Malwarebytes
2013-01-22 16:35 . 2013-01-22 16:35 -------- d-----w- c:\programdata\Malwarebytes
2013-01-22 16:35 . 2013-01-22 19:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-01-22 16:35 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-22 16:03 . 2013-01-22 16:03 -------- d-----w- C:\rsit
2013-01-22 16:03 . 2013-01-22 16:03 -------- d-----w- c:\program files\trend micro
2012-12-30 01:50 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6D694FE0-2E14-49C0-A93E-15676D613C38}\mpengine.dll
2012-12-27 15:05 . 2012-12-27 15:05 -------- d-----w- c:\users\Karel\AppData\Local\4A Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 10:26 . 2012-04-09 17:49 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-09 10:26 . 2011-05-18 06:05 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-19 08:04 . 2012-11-19 08:04 2268 ----a-w- c:\users\Karel\AppData\Roaming\mdbu.bin
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"HTC Sync Loader"="d:\programy\htcUPCTLoader.exe" [2010-09-08 249856]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-10-18 38424]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2010-10-18 38424]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
R3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2011-03-07 18456]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-28 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-05-06 834544]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files (x86)\ICQ7.1\ICQ.exe
TCP: DhcpNameServer = 192.168.88.1
FF - ProfilePath - c:\users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\rl07yjqs.default\
FF - prefs.js: browser.startup.homepage -
www.seznam.cz
FF - ExtSQL: 2013-01-22 20:25;
wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Borderlands 2_is1 - d:\hry\Borderlands 2\unins000.exe
AddRemove-Call of Duty: Black Ops_is1 - d:\hry\call of duty bl.ops\Call of Duty - Black Ops\unins000.exe
AddRemove-DAEMON Tools Toolbar - c:\program files (x86)\DAEMON Tools Toolbar\uninst.exe
AddRemove-Dogfight 1942 (c) City Interactive_is1 - d:\hry\Dogfight 1942\unins000.exe
AddRemove-Inversion_is1 - d:\hry\Inversion\unins000.exe
AddRemove-LEGO Star Wars III The Clone Wars - d:\hry\LEGO.Star.Wars.III.The.Clone.Wars-SKIDROW\LEGO Star Wars III The Clone Wars\Uninstall.exe
AddRemove-Metro 2033 Update 2_is1 - d:\hry\Metro 2033\Metro 2033\unins000.exe
AddRemove-Prototype 2_is1 - d:\hry\Prototype 2\unins000.exe
AddRemove-Sleeping Dogs_is1 - d:\hry\Sleeping Dogs\unins000.exe
AddRemove-Spec Ops The Line_is1 - d:\hry\Spec Ops The Line\unins000.exe
AddRemove-{2527736B-927C-4E5F-A861-6BA616568B80}_is1 - d:\hry\Sniper Elite\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\@&D*]
@=multi:"\00\00\00\00\00@\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00ř\00\00\00\0e\1fş\0e\00´\09Í!¸\01LÍ!This program cannot be run in DOS mode.\0d\0d\0a$\00\00\00\00\00\00\00pÎđ•4ŻžĆ4ŻžĆ4ŻžĆ[Ů5Ć\01ŻžĆ[Ů\00Ć)ŻžĆ[Ů4Ć˝ŻžĆSŮ5Ć1ŻžĆ=×\0dĆ9ŻžĆ4ŻźĆ‘ŻžĆSŮ1Ć'ŻžĆSŮ\00\00"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Celkový čas: 2013-01-23 22:11:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-23 21:11
ComboFix2.txt 2013-01-22 20:50
ComboFix3.txt 2012-06-07 10:06
.
Před spuštěním: Volných bajtů: 419 164 684 288
Po spuštění: Volných bajtů: 418 826 768 384
.
- - End Of File - - E4CC35E33856618C7AFE776236BC8651