Re: poprosim o kontrolu, díky, díky.
Napsal: 22 srp 2013 21:41
ComboFix 13-08-22.01 - Jaro . 08. 2013 22:21:20.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.3692.2330 [GMT 2:00]
Running from: c:\users\Jaro\Desktop\ComboFix.exe
Command switches used :: c:\users\Jaro\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
((((((((((((((((((((((((( Files Created from 2013-07-22 to 2013-08-22 )))))))))))))))))))))))))))))))
.
.
2013-08-22 20:30 . 2013-08-22 20:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-22 16:06 . 2013-08-22 16:06 -------- d-----w- C:\rsit
2013-08-21 20:20 . 2013-08-21 20:48 -------- d-----w- C:\AdwCleaner
2013-08-21 20:15 . 2013-08-21 20:15 -------- d-----w- c:\users\Jaro\AppData\Roaming\Radiocom
2013-08-21 20:15 . 2013-08-21 20:15 -------- d-----w- c:\users\Jaro\RichMedia
2013-08-21 20:15 . 2013-08-21 20:15 -------- d-----w- c:\users\Jaro\AppData\Local\Radiocom
2013-08-20 14:51 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BB435C5A-1FB6-4109-855B-43D5B2C8686F}\mpengine.dll
2013-08-16 15:46 . 2013-08-16 15:48 -------- d-----w- c:\windows\system32\MRT
2013-08-16 10:41 . 2013-08-16 10:41 458064 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-22 20:32 . 2011-07-21 18:46 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-08-21 16:34 . 2012-04-02 05:15 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-21 16:34 . 2011-10-09 14:11 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-16 15:46 . 2011-07-23 19:00 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-08-16 10:41 . 2012-09-19 20:04 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2013-07-09 04:45 . 2013-08-16 10:33 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-05 18:56 . 2013-04-29 16:11 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-05 18:56 . 2012-06-18 14:00 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-07-05 18:56 . 2011-08-21 15:21 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-18 22:22 . 2013-06-18 22:22 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-06-18 22:22 . 2013-06-18 22:22 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-06-18 22:22 . 2013-06-18 22:22 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-06-18 22:22 . 2013-06-18 22:22 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-06-18 22:22 . 2013-06-18 22:22 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-06-18 22:22 . 2013-06-18 22:22 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-06-18 22:22 . 2013-06-18 22:22 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-06-18 22:22 . 2013-06-18 22:22 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-06-18 22:22 . 2013-06-18 22:22 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-06-18 22:22 . 2013-06-18 22:22 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-06-18 22:22 . 2013-06-18 22:22 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-06-18 22:22 . 2013-06-18 22:22 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-06-18 22:22 . 2013-06-18 22:22 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-06-18 22:22 . 2013-06-18 22:22 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-06-18 22:22 . 2013-06-18 22:22 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-06-18 22:22 . 2013-06-18 22:22 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-06-18 22:22 . 2013-06-18 22:22 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-06-18 22:22 . 2013-06-18 22:22 81408 ----a-w- c:\windows\system32\icardie.dll
2013-06-18 22:22 . 2013-06-18 22:22 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-06-18 22:22 . 2013-06-18 22:22 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-06-18 22:22 . 2013-06-18 22:22 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-06-18 22:22 . 2013-06-18 22:22 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-06-18 22:22 . 2013-06-18 22:22 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-06-18 22:22 . 2013-06-18 22:22 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-06-18 22:22 . 2013-06-18 22:22 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-06-18 22:22 . 2013-06-18 22:22 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-06-18 22:22 . 2013-06-18 22:22 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-06-18 22:22 . 2013-06-18 22:22 441856 ----a-w- c:\windows\system32\html.iec
2013-06-18 22:22 . 2013-06-18 22:22 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-06-18 22:22 . 2013-06-18 22:22 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-06-18 22:22 . 2013-06-18 22:22 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-06-18 22:22 . 2013-06-18 22:22 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-06-18 22:22 . 2013-06-18 22:22 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-06-18 22:22 . 2013-06-18 22:22 235008 ----a-w- c:\windows\system32\url.dll
2013-06-18 22:22 . 2013-06-18 22:22 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-06-18 22:22 . 2013-06-18 22:22 216064 ----a-w- c:\windows\system32\msls31.dll
2013-06-18 22:22 . 2013-06-18 22:22 197120 ----a-w- c:\windows\system32\msrating.dll
2013-06-18 22:22 . 2013-06-18 22:22 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-06-18 22:22 . 2013-06-18 22:22 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-06-18 22:22 . 2013-06-18 22:22 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-06-18 22:22 . 2013-06-18 22:22 149504 ----a-w- c:\windows\system32\occache.dll
2013-06-18 22:22 . 2013-06-18 22:22 144896 ----a-w- c:\windows\system32\wextract.exe
2013-06-18 22:22 . 2013-06-18 22:22 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-06-18 22:22 . 2013-06-18 22:22 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-06-18 22:22 . 2013-06-18 22:22 13824 ----a-w- c:\windows\system32\mshta.exe
2013-06-18 22:22 . 2013-06-18 22:22 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-06-18 22:22 . 2013-06-18 22:22 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-06-18 22:22 . 2013-06-18 22:22 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-06-18 22:22 . 2013-06-18 22:22 102912 ----a-w- c:\windows\system32\inseng.dll
2013-06-18 22:20 . 2013-06-18 22:20 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-06-18 22:20 . 2013-06-18 22:20 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-06-18 22:20 . 2013-06-18 22:20 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-06-18 22:20 . 2013-06-18 22:20 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-06-18 22:20 . 2013-06-18 22:20 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-06-18 22:20 . 2013-06-18 22:20 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-06-18 22:20 . 2013-06-18 22:20 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-06-18 22:20 . 2013-06-18 22:20 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-06-18 22:20 . 2013-06-18 22:20 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 296960 ----a-w- c:\windows\system32\d3d10core.dll
2013-06-18 22:20 . 2013-06-18 22:20 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2013-06-18 22:20 . 2013-06-18 22:20 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2013-06-18 22:20 . 2013-06-18 22:20 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2013-06-18 22:20 . 2013-06-18 22:20 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2013-06-18 22:20 . 2013-06-18 22:20 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-06-18 22:20 . 2013-06-18 22:20 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2013-06-18 22:20 . 2013-06-18 22:20 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2013-06-18 22:20 . 2013-06-18 22:20 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2013-06-18 22:20 . 2013-06-18 22:20 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2013-06-18 22:20 . 2013-06-18 22:20 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2013-06-18 22:20 . 2013-06-18 22:20 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2013-06-18 22:20 . 2013-06-18 22:20 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2013-06-18 22:20 . 2013-06-18 22:20 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2013-06-18 22:20 . 2013-06-18 22:20 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2013-06-18 22:20 . 2013-06-18 22:20 1238528 ----a-w- c:\windows\system32\d3d10.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-06 222496]
"Syncables"="c:\program files (x86)\syncables\syncables desktop\Syncables.exe" [2010-07-19 370480]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]
"SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2012-04-19 336952]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"Nikon Message Center 2"="c:\program files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-25 619008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe -d [2011-8-11 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 16:34]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-18 2189416]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-01-07 615584]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-01-07 379040]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"Setwallpaper"="c:\programdata\SetWallpaper.cmd" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearchAssistant = about:blank
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: {{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} -
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Jaro\AppData\Roaming\Mozilla\Firefox\Profiles\rp5dphv0.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
AddRemove-PunkBusterSvc - c:\program files (x86)\Origin Games\Battlefield 3\pbsvc.exe
AddRemove-{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Completion time: 2013-08-22 22:39:14 - machine was rebooted
ComboFix-quarantined-files.txt 2013-08-22 20:39
ComboFix2.txt 2013-08-22 19:56
.
Pre-Run: 79 543 042 048 bytes free
Post-Run: 79 229 231 104 bytes free
.
- - End Of File - - 4CF60A954EBAAABEBCA964AF1062C3C7
A36C5E4F47E84449FF07ED3517B43A31
Upload was successful
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.3692.2330 [GMT 2:00]
Running from: c:\users\Jaro\Desktop\ComboFix.exe
Command switches used :: c:\users\Jaro\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
((((((((((((((((((((((((( Files Created from 2013-07-22 to 2013-08-22 )))))))))))))))))))))))))))))))
.
.
2013-08-22 20:30 . 2013-08-22 20:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-22 16:06 . 2013-08-22 16:06 -------- d-----w- C:\rsit
2013-08-21 20:20 . 2013-08-21 20:48 -------- d-----w- C:\AdwCleaner
2013-08-21 20:15 . 2013-08-21 20:15 -------- d-----w- c:\users\Jaro\AppData\Roaming\Radiocom
2013-08-21 20:15 . 2013-08-21 20:15 -------- d-----w- c:\users\Jaro\RichMedia
2013-08-21 20:15 . 2013-08-21 20:15 -------- d-----w- c:\users\Jaro\AppData\Local\Radiocom
2013-08-20 14:51 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BB435C5A-1FB6-4109-855B-43D5B2C8686F}\mpengine.dll
2013-08-16 15:46 . 2013-08-16 15:48 -------- d-----w- c:\windows\system32\MRT
2013-08-16 10:41 . 2013-08-16 10:41 458064 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-22 20:32 . 2011-07-21 18:46 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-08-21 16:34 . 2012-04-02 05:15 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-21 16:34 . 2011-10-09 14:11 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-16 15:46 . 2011-07-23 19:00 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-08-16 10:41 . 2012-09-19 20:04 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2013-07-09 04:45 . 2013-08-16 10:33 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-05 18:56 . 2013-04-29 16:11 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-05 18:56 . 2012-06-18 14:00 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-07-05 18:56 . 2011-08-21 15:21 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-18 22:22 . 2013-06-18 22:22 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-06-18 22:22 . 2013-06-18 22:22 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-06-18 22:22 . 2013-06-18 22:22 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-06-18 22:22 . 2013-06-18 22:22 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-06-18 22:22 . 2013-06-18 22:22 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-06-18 22:22 . 2013-06-18 22:22 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-06-18 22:22 . 2013-06-18 22:22 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-06-18 22:22 . 2013-06-18 22:22 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-06-18 22:22 . 2013-06-18 22:22 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-06-18 22:22 . 2013-06-18 22:22 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-06-18 22:22 . 2013-06-18 22:22 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-06-18 22:22 . 2013-06-18 22:22 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-06-18 22:22 . 2013-06-18 22:22 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-06-18 22:22 . 2013-06-18 22:22 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-06-18 22:22 . 2013-06-18 22:22 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-06-18 22:22 . 2013-06-18 22:22 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-06-18 22:22 . 2013-06-18 22:22 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-06-18 22:22 . 2013-06-18 22:22 81408 ----a-w- c:\windows\system32\icardie.dll
2013-06-18 22:22 . 2013-06-18 22:22 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-06-18 22:22 . 2013-06-18 22:22 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-06-18 22:22 . 2013-06-18 22:22 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-06-18 22:22 . 2013-06-18 22:22 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-06-18 22:22 . 2013-06-18 22:22 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-06-18 22:22 . 2013-06-18 22:22 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-06-18 22:22 . 2013-06-18 22:22 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-06-18 22:22 . 2013-06-18 22:22 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-06-18 22:22 . 2013-06-18 22:22 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-06-18 22:22 . 2013-06-18 22:22 441856 ----a-w- c:\windows\system32\html.iec
2013-06-18 22:22 . 2013-06-18 22:22 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-06-18 22:22 . 2013-06-18 22:22 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-06-18 22:22 . 2013-06-18 22:22 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-06-18 22:22 . 2013-06-18 22:22 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-06-18 22:22 . 2013-06-18 22:22 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-06-18 22:22 . 2013-06-18 22:22 235008 ----a-w- c:\windows\system32\url.dll
2013-06-18 22:22 . 2013-06-18 22:22 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-06-18 22:22 . 2013-06-18 22:22 216064 ----a-w- c:\windows\system32\msls31.dll
2013-06-18 22:22 . 2013-06-18 22:22 197120 ----a-w- c:\windows\system32\msrating.dll
2013-06-18 22:22 . 2013-06-18 22:22 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-06-18 22:22 . 2013-06-18 22:22 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-06-18 22:22 . 2013-06-18 22:22 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-06-18 22:22 . 2013-06-18 22:22 149504 ----a-w- c:\windows\system32\occache.dll
2013-06-18 22:22 . 2013-06-18 22:22 144896 ----a-w- c:\windows\system32\wextract.exe
2013-06-18 22:22 . 2013-06-18 22:22 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-06-18 22:22 . 2013-06-18 22:22 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-06-18 22:22 . 2013-06-18 22:22 13824 ----a-w- c:\windows\system32\mshta.exe
2013-06-18 22:22 . 2013-06-18 22:22 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-06-18 22:22 . 2013-06-18 22:22 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-06-18 22:22 . 2013-06-18 22:22 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-06-18 22:22 . 2013-06-18 22:22 102912 ----a-w- c:\windows\system32\inseng.dll
2013-06-18 22:20 . 2013-06-18 22:20 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-06-18 22:20 . 2013-06-18 22:20 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-06-18 22:20 . 2013-06-18 22:20 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-06-18 22:20 . 2013-06-18 22:20 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-06-18 22:20 . 2013-06-18 22:20 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-06-18 22:20 . 2013-06-18 22:20 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-06-18 22:20 . 2013-06-18 22:20 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-06-18 22:20 . 2013-06-18 22:20 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-06-18 22:20 . 2013-06-18 22:20 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 296960 ----a-w- c:\windows\system32\d3d10core.dll
2013-06-18 22:20 . 2013-06-18 22:20 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2013-06-18 22:20 . 2013-06-18 22:20 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2013-06-18 22:20 . 2013-06-18 22:20 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2013-06-18 22:20 . 2013-06-18 22:20 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-18 22:20 . 2013-06-18 22:20 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2013-06-18 22:20 . 2013-06-18 22:20 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-06-18 22:20 . 2013-06-18 22:20 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2013-06-18 22:20 . 2013-06-18 22:20 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2013-06-18 22:20 . 2013-06-18 22:20 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2013-06-18 22:20 . 2013-06-18 22:20 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2013-06-18 22:20 . 2013-06-18 22:20 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2013-06-18 22:20 . 2013-06-18 22:20 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2013-06-18 22:20 . 2013-06-18 22:20 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2013-06-18 22:20 . 2013-06-18 22:20 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2013-06-18 22:20 . 2013-06-18 22:20 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2013-06-18 22:20 . 2013-06-18 22:20 1238528 ----a-w- c:\windows\system32\d3d10.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-06 222496]
"Syncables"="c:\program files (x86)\syncables\syncables desktop\Syncables.exe" [2010-07-19 370480]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]
"SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2012-04-19 336952]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"Nikon Message Center 2"="c:\program files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-25 619008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe -d [2011-8-11 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 16:34]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-18 2189416]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-01-07 615584]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-01-07 379040]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"Setwallpaper"="c:\programdata\SetWallpaper.cmd" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearchAssistant = about:blank
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: {{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} -
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Jaro\AppData\Roaming\Mozilla\Firefox\Profiles\rp5dphv0.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
AddRemove-PunkBusterSvc - c:\program files (x86)\Origin Games\Battlefield 3\pbsvc.exe
AddRemove-{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Completion time: 2013-08-22 22:39:14 - machine was rebooted
ComboFix-quarantined-files.txt 2013-08-22 20:39
ComboFix2.txt 2013-08-22 19:56
.
Pre-Run: 79 543 042 048 bytes free
Post-Run: 79 229 231 104 bytes free
.
- - End Of File - - 4CF60A954EBAAABEBCA964AF1062C3C7
A36C5E4F47E84449FF07ED3517B43A31
Upload was successful