Re: prosim o kontrolu logu ( zavirovany system )
Napsal: 09 lis 2013 14:01
ComboFix 13-11-07.01 - Tatana 09.11.2013 13:45:15.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4074.2475 [GMT 1:00]
Spuštěný z: c:\users\Tatana\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Windows Live\Messenger\msacm32.dll
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-09 do 2013-11-09 )))))))))))))))))))))))))))))))
.
.
2013-11-09 12:50 . 2013-11-09 12:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-08 14:44 . 2013-10-16 00:20 10280728 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E8B05C1B-3760-4C4B-985D-22511BE3A24D}\mpengine.dll
2013-11-04 21:51 . 2013-11-05 15:28 -------- d-----w- C:\AdwCleaner
2013-11-02 16:29 . 2013-11-02 16:29 -------- d-----w- c:\programdata\Malwarebytes
2013-11-02 15:39 . 2013-11-02 15:39 -------- d-----w- c:\program files\trend micro
2013-11-02 15:39 . 2013-11-02 15:40 -------- d-----w- C:\rsit
2013-10-30 06:37 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-10-30 06:36 . 2013-07-03 04:05 76800 ----a-w- c:\windows\system32\drivers\hidclass.sys
2013-10-30 06:35 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2013-10-30 06:34 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2013-10-30 06:33 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-10-30 06:32 . 2012-06-06 06:05 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2013-10-30 06:32 . 2012-06-06 06:05 61440 ----a-w- c:\program files\Common Files\System\ado\msador15.dll
2013-10-30 06:32 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2013-10-30 06:32 . 2012-06-06 06:05 1499136 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2013-10-30 06:32 . 2012-06-06 06:05 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2013-10-30 06:32 . 2012-06-06 06:02 1133568 ----a-w- c:\windows\system32\cdosys.dll
2013-10-30 06:32 . 2012-06-06 05:05 143360 ----a-w- c:\program files (x86)\Common Files\System\ado\msjro.dll
2013-10-30 06:32 . 2012-06-06 05:05 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2013-10-30 06:32 . 2012-06-06 05:05 57344 ----a-w- c:\program files (x86)\Common Files\System\ado\msador15.dll
2013-10-30 06:32 . 2012-06-06 05:05 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2013-10-30 06:32 . 2012-06-06 05:05 212992 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2013-10-30 06:32 . 2012-06-06 05:05 1019904 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2013-10-30 06:32 . 2012-06-06 05:03 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
2013-10-30 06:22 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-30 06:22 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2013-10-30 06:22 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2013-10-30 06:22 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2013-10-30 06:22 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2013-10-30 06:06 . 2013-10-30 06:06 -------- d-----w- c:\windows\SysWow64\Wat
2013-10-30 06:06 . 2013-10-30 06:06 -------- d-----w- c:\windows\system32\Wat
2013-10-30 04:51 . 2012-07-26 07:40 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
2013-10-30 04:51 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-10-30 04:51 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-10-30 04:44 . 2013-10-30 04:44 -------- d-----w- c:\program files (x86)\MSXML 4.0
2013-10-30 04:24 . 2013-10-30 04:24 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-10-30 04:18 . 2013-10-30 04:18 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-10-30 04:18 . 2013-10-30 04:18 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-10-30 03:58 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-10-30 03:58 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-10-30 03:58 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-10-30 03:58 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-10-30 03:58 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-10-30 03:58 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-10-30 03:58 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-10-30 03:45 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-10-30 03:45 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-10-30 03:45 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-10-30 03:45 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-10-30 03:45 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-10-29 23:57 . 2013-10-29 23:57 -------- d-----w- c:\program files (x86)\TeamViewer
2013-10-29 20:52 . 2013-10-29 20:52 -------- d-----w- C:\13f5c8c266c21ce85f7afc69
2013-10-29 20:03 . 2013-10-29 20:40 -------- d-----w- C:\d3a2fb96d16e6833d95c8fa1
2013-10-29 03:43 . 2012-06-22 11:01 22704 ----a-w- c:\windows\system32\drivers\EsgScanner.sys
2013-10-29 03:43 . 2013-10-29 03:43 -------- d-----w- C:\sh4ldr
2013-10-29 03:43 . 2013-10-29 03:43 -------- d-----w- c:\program files\Enigma Software Group
2013-10-29 03:43 . 2013-10-29 03:43 -------- d-----w- c:\windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP
2013-10-29 03:10 . 2011-06-16 05:49 199680 ----a-w- c:\windows\system32\xmllite.dll
2013-10-29 03:10 . 2012-10-09 18:17 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-10-29 03:10 . 2012-10-09 18:17 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2013-10-29 03:10 . 2012-10-09 17:40 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2013-10-29 03:10 . 2012-10-09 17:40 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2013-10-29 03:04 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
2013-10-29 03:03 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2013-10-29 03:02 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-10-28 04:01 . 2013-10-28 04:01 -------- d-----w- c:\windows\OemDrv
2013-10-28 03:58 . 2013-10-28 03:58 -------- d-----w- c:\program files (x86)\TOSHIBA Corporation
2013-10-28 03:58 . 2013-10-28 03:58 -------- d-----w- c:\windows\SysWow64\Macromed
2013-10-28 03:54 . 2013-10-28 03:56 -------- d-----w- c:\programdata\TOSHIBA
2013-10-28 03:54 . 2011-02-17 15:42 99320 ----a-w- c:\windows\system32\tosWirelessLANIndicatorCP.dll
2013-10-28 03:54 . 2010-03-18 08:36 827728 ----a-w- c:\windows\system32\msvcr100.dll
2013-10-28 03:54 . 2010-03-18 08:36 607568 ----a-w- c:\windows\system32\msvcp100.dll
2013-10-28 03:53 . 2013-10-28 03:53 -------- d-----w- c:\windows\SysWow64\sda
2013-10-28 03:53 . 2010-07-20 16:43 247400 ----a-w- c:\windows\system32\drivers\RtsUStor.sys
2013-10-28 03:53 . 2010-07-20 16:42 9112168 ----a-w- c:\windows\SysWow64\RtsUStoricon.dll
2013-10-28 03:53 . 2010-07-20 16:42 422504 ----a-w- c:\windows\system32\RtsUStor.dll
2013-10-28 03:52 . 2009-06-18 20:42 40832 ----a-w- c:\windows\system32\drivers\TosBtCi.dll
2013-10-28 03:49 . 2013-10-28 03:49 -------- d-----w- c:\program files\Synaptics
2013-10-28 03:48 . 2013-10-28 03:48 -------- d-----w- c:\windows\system32\nn-NO
2013-10-28 03:48 . 2013-10-28 03:48 -------- d-----w- c:\windows\Options
2013-10-28 03:48 . 2013-10-28 03:48 -------- d-----w- c:\program files (x86)\Atheros
2013-10-28 03:48 . 2010-12-20 18:20 63648 ----a-w- c:\windows\system32\athihvui.dll
2013-10-28 03:48 . 2010-12-20 18:20 443040 ----a-w- c:\windows\system32\athihvs.dll
2013-10-28 03:48 . 2010-12-17 18:46 2675712 ----a-w- c:\windows\system32\drivers\athrx.sys
2013-10-28 03:47 . 2013-10-28 03:48 -------- d-----w- c:\programdata\Atheros
2013-10-28 03:46 . 2013-10-28 03:46 -------- d-----w- c:\windows\SysWow64\RTCOM
2013-10-28 03:46 . 2013-10-28 03:46 -------- d-----w- c:\program files\Realtek
2013-10-28 03:43 . 2010-12-02 00:12 1359976 ----a-w- c:\windows\system32\nvgenco64hda.dll
2013-10-28 03:43 . 2010-11-11 14:10 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2013-10-28 03:43 . 2010-11-11 14:10 155752 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2013-10-28 03:39 . 2013-10-28 03:55 -------- d-----w- c:\windows\Downloaded Installations
2013-10-28 03:37 . 2011-01-12 16:51 439320 ----a-w- c:\windows\system32\drivers\iaStor.sys
2013-10-28 03:37 . 2013-10-28 03:37 -------- d-----w- c:\programdata\NVIDIA
2013-10-28 03:35 . 2013-10-28 03:35 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2013-10-28 03:31 . 2011-02-01 12:06 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
2013-10-28 03:31 . 2013-10-28 03:31 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
2013-10-28 03:31 . 2013-10-28 03:31 -------- d-----w- C:\Intel
2013-10-28 03:29 . 2013-10-28 03:37 -------- d-----w- c:\program files (x86)\Intel
2013-10-28 03:29 . 2010-10-04 12:02 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2013-10-28 01:43 . 2013-11-05 15:28 -------- d-----w- c:\programdata\Uniblue
2013-10-28 01:27 . 2013-10-28 01:44 -------- d-----w- c:\program files (x86)\Mobogenie
2013-10-28 01:27 . 2013-10-28 01:27 -------- d-----w- c:\program files (x86)\iRobinHood
2013-10-28 01:12 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2013-10-28 01:12 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2013-10-28 01:12 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-10-28 01:08 . 2013-10-28 01:08 -------- d--h--w- c:\windows\msdownld.tmp
2013-10-28 01:07 . 2013-10-28 01:08 -------- d-----w- c:\program files (x86)\eBay
2013-10-28 01:06 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2013-10-28 01:06 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2013-10-28 01:06 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2013-10-28 01:06 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2013-10-28 01:06 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2013-10-28 01:06 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2013-10-28 01:06 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2013-10-28 01:06 . 2012-06-02 14:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2013-10-28 01:06 . 2012-06-02 14:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2013-10-28 01:05 . 2013-10-28 01:05 -------- d-----w- c:\programdata\ToshibaEurope
2013-10-28 01:02 . 2013-10-29 20:41 -------- d-----w- c:\users\Tatana
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-30 04:25 . 2013-10-30 04:25 204800 ----a-w- c:\windows\SysWow64\webcheck.dll
2013-10-30 04:25 . 2013-10-30 04:25 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-10-28 01:03 . 2010-06-24 09:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-10-02 21:14 . 2013-10-02 21:14 58192 ----a-w- c:\windows\system32\drivers\lsnfd.sys
2013-09-03 13:35 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-29 01:48 . 2013-11-02 15:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{54E67346-EE5A-45B6-82AA-4F0BB28C79C2}]
2013-10-23 12:58 769320 ----a-w- c:\program files (x86)\iRobinHood\iRobinHood Addon\iRobinHood.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-02-18 845176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2011-01-07 1406248]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-11-29 1294712]
"mobilegeni daemon"="c:\program files (x86)\Mobogenie\DaemonProcess.exe" [2013-10-28 738496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-02-18 845176]
.
c:\users\Tatana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TeamViewer 8.lnk - c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe [2013-10-30 12631904]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 BtFilter;Bluetooth LowerFilter Class Filter Driver;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
R3 EsgScanner;EsgScanner;c:\windows\system32\DRIVERS\EsgScanner.sys;c:\windows\SYSNATIVE\DRIVERS\EsgScanner.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 lsnfd;lsnfd;c:\windows\system32\drivers\lsnfd.sys;c:\windows\SYSNATIVE\drivers\lsnfd.sys [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys;c:\windows\SYSNATIVE\DRIVERS\CeKbFilter.sys [x]
S3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2011-02-10 1546720]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-12-08 710040]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\TOSHIBA\Registration\ToshibaReminder.exe" [2011-05-03 150992]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Přidat do aplikace TOSHIBA Bulletin Board - c:\program files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
IE: {{54E67346-EE5A-45B6-82AA-4F0BB28C79C2} - {54E67346-EE5A-45B6-82AA-4F0BB28C79C2} - c:\program files (x86)\iRobinHood\iRobinHood Addon\iRobinHood.dll
TCP: DhcpNameServer = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{298cb7ae-9843-494b-ac62-9fffff634973} - c:\program files (x86)\Pass-Widget\134.dll
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Linksicle - c:\program files (x86)\Linksicle\Uninstall.exe
AddRemove-{858366ac-2d91-41f0-8765-0c809058bbeb} - c:\program files (x86)\Pass-Widget\Uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-11-09 13:52:15
ComboFix-quarantined-files.txt 2013-11-09 12:52
.
Před spuštěním: Volných bajtů: 273 624 576 000
Po spuštění: Volných bajtů: 276 473 303 040
.
- - End Of File - - 4C58411B4FF2CFC6CA1438ED202DD689
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4074.2475 [GMT 1:00]
Spuštěný z: c:\users\Tatana\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Windows Live\Messenger\msacm32.dll
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-09 do 2013-11-09 )))))))))))))))))))))))))))))))
.
.
2013-11-09 12:50 . 2013-11-09 12:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-08 14:44 . 2013-10-16 00:20 10280728 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E8B05C1B-3760-4C4B-985D-22511BE3A24D}\mpengine.dll
2013-11-04 21:51 . 2013-11-05 15:28 -------- d-----w- C:\AdwCleaner
2013-11-02 16:29 . 2013-11-02 16:29 -------- d-----w- c:\programdata\Malwarebytes
2013-11-02 15:39 . 2013-11-02 15:39 -------- d-----w- c:\program files\trend micro
2013-11-02 15:39 . 2013-11-02 15:40 -------- d-----w- C:\rsit
2013-10-30 06:37 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-10-30 06:36 . 2013-07-03 04:05 76800 ----a-w- c:\windows\system32\drivers\hidclass.sys
2013-10-30 06:35 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2013-10-30 06:34 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2013-10-30 06:33 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-10-30 06:32 . 2012-06-06 06:05 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2013-10-30 06:32 . 2012-06-06 06:05 61440 ----a-w- c:\program files\Common Files\System\ado\msador15.dll
2013-10-30 06:32 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2013-10-30 06:32 . 2012-06-06 06:05 1499136 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2013-10-30 06:32 . 2012-06-06 06:05 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2013-10-30 06:32 . 2012-06-06 06:02 1133568 ----a-w- c:\windows\system32\cdosys.dll
2013-10-30 06:32 . 2012-06-06 05:05 143360 ----a-w- c:\program files (x86)\Common Files\System\ado\msjro.dll
2013-10-30 06:32 . 2012-06-06 05:05 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2013-10-30 06:32 . 2012-06-06 05:05 57344 ----a-w- c:\program files (x86)\Common Files\System\ado\msador15.dll
2013-10-30 06:32 . 2012-06-06 05:05 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2013-10-30 06:32 . 2012-06-06 05:05 212992 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2013-10-30 06:32 . 2012-06-06 05:05 1019904 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2013-10-30 06:32 . 2012-06-06 05:03 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
2013-10-30 06:22 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-30 06:22 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2013-10-30 06:22 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2013-10-30 06:22 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2013-10-30 06:22 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2013-10-30 06:06 . 2013-10-30 06:06 -------- d-----w- c:\windows\SysWow64\Wat
2013-10-30 06:06 . 2013-10-30 06:06 -------- d-----w- c:\windows\system32\Wat
2013-10-30 04:51 . 2012-07-26 07:40 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
2013-10-30 04:51 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-10-30 04:51 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-10-30 04:44 . 2013-10-30 04:44 -------- d-----w- c:\program files (x86)\MSXML 4.0
2013-10-30 04:24 . 2013-10-30 04:24 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-10-30 04:18 . 2013-10-30 04:18 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-10-30 04:18 . 2013-10-30 04:18 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-10-30 03:58 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-10-30 03:58 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-10-30 03:58 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-10-30 03:58 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-10-30 03:58 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-10-30 03:58 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-10-30 03:58 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-10-30 03:45 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-10-30 03:45 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-10-30 03:45 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-10-30 03:45 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-10-30 03:45 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-10-29 23:57 . 2013-10-29 23:57 -------- d-----w- c:\program files (x86)\TeamViewer
2013-10-29 20:52 . 2013-10-29 20:52 -------- d-----w- C:\13f5c8c266c21ce85f7afc69
2013-10-29 20:03 . 2013-10-29 20:40 -------- d-----w- C:\d3a2fb96d16e6833d95c8fa1
2013-10-29 03:43 . 2012-06-22 11:01 22704 ----a-w- c:\windows\system32\drivers\EsgScanner.sys
2013-10-29 03:43 . 2013-10-29 03:43 -------- d-----w- C:\sh4ldr
2013-10-29 03:43 . 2013-10-29 03:43 -------- d-----w- c:\program files\Enigma Software Group
2013-10-29 03:43 . 2013-10-29 03:43 -------- d-----w- c:\windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP
2013-10-29 03:10 . 2011-06-16 05:49 199680 ----a-w- c:\windows\system32\xmllite.dll
2013-10-29 03:10 . 2012-10-09 18:17 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-10-29 03:10 . 2012-10-09 18:17 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2013-10-29 03:10 . 2012-10-09 17:40 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2013-10-29 03:10 . 2012-10-09 17:40 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2013-10-29 03:04 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
2013-10-29 03:03 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2013-10-29 03:02 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-10-28 04:01 . 2013-10-28 04:01 -------- d-----w- c:\windows\OemDrv
2013-10-28 03:58 . 2013-10-28 03:58 -------- d-----w- c:\program files (x86)\TOSHIBA Corporation
2013-10-28 03:58 . 2013-10-28 03:58 -------- d-----w- c:\windows\SysWow64\Macromed
2013-10-28 03:54 . 2013-10-28 03:56 -------- d-----w- c:\programdata\TOSHIBA
2013-10-28 03:54 . 2011-02-17 15:42 99320 ----a-w- c:\windows\system32\tosWirelessLANIndicatorCP.dll
2013-10-28 03:54 . 2010-03-18 08:36 827728 ----a-w- c:\windows\system32\msvcr100.dll
2013-10-28 03:54 . 2010-03-18 08:36 607568 ----a-w- c:\windows\system32\msvcp100.dll
2013-10-28 03:53 . 2013-10-28 03:53 -------- d-----w- c:\windows\SysWow64\sda
2013-10-28 03:53 . 2010-07-20 16:43 247400 ----a-w- c:\windows\system32\drivers\RtsUStor.sys
2013-10-28 03:53 . 2010-07-20 16:42 9112168 ----a-w- c:\windows\SysWow64\RtsUStoricon.dll
2013-10-28 03:53 . 2010-07-20 16:42 422504 ----a-w- c:\windows\system32\RtsUStor.dll
2013-10-28 03:52 . 2009-06-18 20:42 40832 ----a-w- c:\windows\system32\drivers\TosBtCi.dll
2013-10-28 03:49 . 2013-10-28 03:49 -------- d-----w- c:\program files\Synaptics
2013-10-28 03:48 . 2013-10-28 03:48 -------- d-----w- c:\windows\system32\nn-NO
2013-10-28 03:48 . 2013-10-28 03:48 -------- d-----w- c:\windows\Options
2013-10-28 03:48 . 2013-10-28 03:48 -------- d-----w- c:\program files (x86)\Atheros
2013-10-28 03:48 . 2010-12-20 18:20 63648 ----a-w- c:\windows\system32\athihvui.dll
2013-10-28 03:48 . 2010-12-20 18:20 443040 ----a-w- c:\windows\system32\athihvs.dll
2013-10-28 03:48 . 2010-12-17 18:46 2675712 ----a-w- c:\windows\system32\drivers\athrx.sys
2013-10-28 03:47 . 2013-10-28 03:48 -------- d-----w- c:\programdata\Atheros
2013-10-28 03:46 . 2013-10-28 03:46 -------- d-----w- c:\windows\SysWow64\RTCOM
2013-10-28 03:46 . 2013-10-28 03:46 -------- d-----w- c:\program files\Realtek
2013-10-28 03:43 . 2010-12-02 00:12 1359976 ----a-w- c:\windows\system32\nvgenco64hda.dll
2013-10-28 03:43 . 2010-11-11 14:10 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2013-10-28 03:43 . 2010-11-11 14:10 155752 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2013-10-28 03:39 . 2013-10-28 03:55 -------- d-----w- c:\windows\Downloaded Installations
2013-10-28 03:37 . 2011-01-12 16:51 439320 ----a-w- c:\windows\system32\drivers\iaStor.sys
2013-10-28 03:37 . 2013-10-28 03:37 -------- d-----w- c:\programdata\NVIDIA
2013-10-28 03:35 . 2013-10-28 03:35 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2013-10-28 03:31 . 2011-02-01 12:06 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
2013-10-28 03:31 . 2013-10-28 03:31 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
2013-10-28 03:31 . 2013-10-28 03:31 -------- d-----w- C:\Intel
2013-10-28 03:29 . 2013-10-28 03:37 -------- d-----w- c:\program files (x86)\Intel
2013-10-28 03:29 . 2010-10-04 12:02 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2013-10-28 01:43 . 2013-11-05 15:28 -------- d-----w- c:\programdata\Uniblue
2013-10-28 01:27 . 2013-10-28 01:44 -------- d-----w- c:\program files (x86)\Mobogenie
2013-10-28 01:27 . 2013-10-28 01:27 -------- d-----w- c:\program files (x86)\iRobinHood
2013-10-28 01:12 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2013-10-28 01:12 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2013-10-28 01:12 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-10-28 01:08 . 2013-10-28 01:08 -------- d--h--w- c:\windows\msdownld.tmp
2013-10-28 01:07 . 2013-10-28 01:08 -------- d-----w- c:\program files (x86)\eBay
2013-10-28 01:06 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2013-10-28 01:06 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2013-10-28 01:06 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2013-10-28 01:06 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2013-10-28 01:06 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2013-10-28 01:06 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2013-10-28 01:06 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2013-10-28 01:06 . 2012-06-02 14:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2013-10-28 01:06 . 2012-06-02 14:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2013-10-28 01:05 . 2013-10-28 01:05 -------- d-----w- c:\programdata\ToshibaEurope
2013-10-28 01:02 . 2013-10-29 20:41 -------- d-----w- c:\users\Tatana
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-30 04:25 . 2013-10-30 04:25 204800 ----a-w- c:\windows\SysWow64\webcheck.dll
2013-10-30 04:25 . 2013-10-30 04:25 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-10-28 01:03 . 2010-06-24 09:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-10-02 21:14 . 2013-10-02 21:14 58192 ----a-w- c:\windows\system32\drivers\lsnfd.sys
2013-09-03 13:35 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-29 01:48 . 2013-11-02 15:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{54E67346-EE5A-45B6-82AA-4F0BB28C79C2}]
2013-10-23 12:58 769320 ----a-w- c:\program files (x86)\iRobinHood\iRobinHood Addon\iRobinHood.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-02-18 845176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2011-01-07 1406248]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-11-29 1294712]
"mobilegeni daemon"="c:\program files (x86)\Mobogenie\DaemonProcess.exe" [2013-10-28 738496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-02-18 845176]
.
c:\users\Tatana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TeamViewer 8.lnk - c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe [2013-10-30 12631904]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 BtFilter;Bluetooth LowerFilter Class Filter Driver;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
R3 EsgScanner;EsgScanner;c:\windows\system32\DRIVERS\EsgScanner.sys;c:\windows\SYSNATIVE\DRIVERS\EsgScanner.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 lsnfd;lsnfd;c:\windows\system32\drivers\lsnfd.sys;c:\windows\SYSNATIVE\drivers\lsnfd.sys [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys;c:\windows\SYSNATIVE\DRIVERS\CeKbFilter.sys [x]
S3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2011-02-10 1546720]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-12-08 710040]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\TOSHIBA\Registration\ToshibaReminder.exe" [2011-05-03 150992]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Přidat do aplikace TOSHIBA Bulletin Board - c:\program files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
IE: {{54E67346-EE5A-45B6-82AA-4F0BB28C79C2} - {54E67346-EE5A-45B6-82AA-4F0BB28C79C2} - c:\program files (x86)\iRobinHood\iRobinHood Addon\iRobinHood.dll
TCP: DhcpNameServer = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{298cb7ae-9843-494b-ac62-9fffff634973} - c:\program files (x86)\Pass-Widget\134.dll
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Linksicle - c:\program files (x86)\Linksicle\Uninstall.exe
AddRemove-{858366ac-2d91-41f0-8765-0c809058bbeb} - c:\program files (x86)\Pass-Widget\Uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-11-09 13:52:15
ComboFix-quarantined-files.txt 2013-11-09 12:52
.
Před spuštěním: Volných bajtů: 273 624 576 000
Po spuštění: Volných bajtů: 276 473 303 040
.
- - End Of File - - 4C58411B4FF2CFC6CA1438ED202DD689