Re: Pekelně zpomalený PC
Napsal: 28 dub 2014 12:37
ComboFix 14-04-26.01 - Sett 28.04.2014 13:18:59.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3070.1914 [GMT 2:00]
Spuštěný z: c:\documents and settings\Sett\Plocha\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Data aplikací\HirezPipeError.txt
c:\documents and settings\Sett\WINDOWS
C:\END
c:\windows\IsUn0405.exe
c:\windows\Readme.txt
c:\windows\system32\Cache
c:\windows\system32\Cache\05b3566814c1c2ec.fb
c:\windows\system32\Cache\075884af680ff6dc.fb
c:\windows\system32\Cache\106510aea847404a.fb
c:\windows\system32\Cache\17cae453d65bd7d5.fb
c:\windows\system32\Cache\227113dfa1ca894d.fb
c:\windows\system32\Cache\26c630d098e22dd5.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\2efed7725b9c9b79.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\332f5cf92a2acb12.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\3d0c20e52984bab4.fb
c:\windows\system32\Cache\450d477ff55871e4.fb
c:\windows\system32\Cache\49fbbc5a8678d502.fb
c:\windows\system32\Cache\57b8735085c2d402.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\5da898cfcc3a7e94.fb
c:\windows\system32\Cache\5f792de28eabf493.fb
c:\windows\system32\Cache\5fe642af980d0463.fb
c:\windows\system32\Cache\601fcb27b6af3e27.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\613e8ce7ab7106af.fb
c:\windows\system32\Cache\633a76311867bd11.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\691f14230153a9e1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6cb409d7ac73d9f1.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\7614bd6cfa99e546.fb
c:\windows\system32\Cache\77664b6ccc36be9f.fb
c:\windows\system32\Cache\77a63fce52270c47.fb
c:\windows\system32\Cache\881b3593316772f0.fb
c:\windows\system32\Cache\895b0fa307ac2927.fb
c:\windows\system32\Cache\95f567698be8a182.fb
c:\windows\system32\Cache\98657d0579ae1930.fb
c:\windows\system32\Cache\a0fe2528705655a0.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\ad92d44a8edfad97.fb
c:\windows\system32\Cache\b9040adb9f0fae54.fb
c:\windows\system32\Cache\bf0ef6c221611fc4.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\cdf4b759b4266804.fb
c:\windows\system32\Cache\cec006b864adbfa2.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d5c0f4e7bbe35bf3.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\d9ca663388d21ec0.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\f2cda51fd108941f.fb
c:\windows\system32\Cache\f34d8db84131d925.fb
c:\windows\system32\Cache\f469d1e5b4a9e1a7.fb
c:\windows\system32\Cache\f814b42f6b1e3213.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\Oleaut32.1
c:\windows\system32\SET268.tmp
c:\windows\system32\SET26D.tmp
c:\windows\system32\x.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_WSYSSVC
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-28 do 2014-04-28 )))))))))))))))))))))))))))))))
.
.
2014-04-27 08:40 . 2014-04-27 08:40 -------- d-----w- c:\documents and settings\Sett\Data aplikací\Malwarebytes
2014-04-27 08:39 . 2014-04-27 08:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2014-04-26 22:41 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-04-26 21:22 . 2014-04-26 21:26 -------- d-----w- c:\program files\trend micro
2014-04-26 21:22 . 2014-04-26 21:26 -------- d-----w- C:\rsit
2014-04-19 23:27 . 2014-04-19 23:29 -------- d-----w- c:\documents and settings\Sett\Data aplikací\deluge
2014-04-07 19:22 . 2014-04-07 19:22 -------- d-----w- c:\documents and settings\Sett\Data aplikací\Awesomium
2014-04-07 19:21 . 2014-04-07 19:21 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Hi-Rez Studios
2014-04-06 00:31 . 2013-06-28 09:44 27776 ----a-w- c:\windows\system32\drivers\lgandnetmodem.sys
2014-04-06 00:31 . 2013-04-18 14:09 23168 ----a-w- c:\windows\system32\drivers\lgandnetdiag.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-18 13:02 . 2011-12-23 11:32 199960 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-03-31 14:11 . 2010-11-12 12:19 211224 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-03-31 14:11 . 2010-09-07 02:48 108312 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2014-03-27 20:15 . 2010-12-08 03:12 193304 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-03-27 20:14 . 2013-08-01 14:06 123160 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-03-27 20:04 . 2012-04-19 02:50 150296 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-03-27 20:04 . 2013-02-08 02:37 238872 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-03-27 20:03 . 2010-09-07 02:48 28440 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-03-27 20:03 . 2011-12-23 11:32 22296 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
2014-03-21 15:57 . 2014-01-30 11:42 42272 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-03-12 13:33 . 2012-04-08 17:17 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 13:33 . 2012-03-14 05:20 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-12 13:33 . 2014-02-21 16:33 5777288 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-02-07 17:24 . 2014-02-07 16:43 94336 ----a-w- c:\windows\system32\drivers\IT9135BDA.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony PC Companion"="c:\program files\Sony\Sony PC Companion\PCCompanion.exe" [2013-10-31 449760]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-26 19522592]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-09-04 767312]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-10-19 1983816]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-04-06 5180432]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"VICTORY Gaming Keyboard"="c:\program files\Gaming Keyboard\Monitor.exe" [2013-04-09 270336]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"Printsrv"="c:\windows\System32\Printing_Admin_Scripts\en-US\drvupd.vbs" [2014-01-11 579]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2014\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamersFirst LIVE!.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\GamersFirst LIVE!.lnk
backup=c:\windows\pss\GamersFirst LIVE!.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena Messenger\\Room\\garena_room.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\Sett\\Plocha\\NFS\\Need For Speed - Most Wanted\\Speed.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Games\\Warcraft III\\Warcraft III.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\java.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer_Service.exe"=
"c:\\Games\\Northland\\Game.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"c:\\Documents and Settings\\Sett\\Data aplikací\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Garena Messenger\\ggdllhost.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgmfapx.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"58090:TCP"= 58090:TCP:Pando Media Booster
"58090:UDP"= 58090:UDP:Pando Media Booster
"58866:TCP"= 58866:TCP:Pando Media Booster
"58866:UDP"= 58866:UDP:Pando Media Booster
"22:TCP"= 22:TCP:192.168.0.120/255.255.255.255:Enabled:Sivi_PC
"57267:TCP"= 57267:TCP:Pando Media Booster
"57267:UDP"= 57267:UDP:Pando Media Booster
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [19.4.2012 4:50 150296]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [8.2.2013 4:37 238872]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7.9.2010 4:48 28440]
R1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [1.8.2013 16:06 123160]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [23.12.2011 13:32 199960]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [23.12.2011 13:32 22296]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [8.12.2010 5:12 193304]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [12.11.2010 14:19 211224]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [30.1.2014 13:42 42272]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [30.10.2013 12:34 203024]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [30.10.2013 12:34 103696]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2014\avgidsagent.exe [18.4.2014 15:22 3645456]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2014\avgwdsvc.exe [27.3.2014 22:10 291912]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\games\SMITE\HiPatchService.exe [7.4.2014 21:21 9216]
R2 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [15.7.2007 4:37 27992]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [9.10.2013 10:58 3275136]
R2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [4.3.2013 23:06 3560800]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [17.4.2013 15:11 242240]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [28.4.2011 21:19 44032]
R3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2.8.2012 12:53 155824]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\drivers\VBoxNetFlt.sys [15.10.2013 14:42 126224]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [23.10.2013 9:15 172192]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [28.4.2011 21:17 1691480]
S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys [6.4.2014 2:31 23168]
S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys [6.4.2014 2:31 27776]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [21.6.2012 20:41 112640]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2.8.2012 12:55 12400]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Messenger\Room\safedrv.sys --> c:\program files\Garena Messenger\Room\safedrv.sys [?]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [7.8.2012 9:37 100480]
S3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\drivers\IT9135BDA.sys [7.2.2014 18:43 94336]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [10.5.2013 21:52 25088]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [15.10.2013 14:42 114960]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - SONY_PC_COMPANION
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-26 03:19 1078088 ----a-w- c:\program files\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 13:33]
.
2014-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-26 13:54]
.
2014-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-26 13:54]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.10.10.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Sett\Data aplikací\Mozilla\Firefox\Profiles\d103pnm3.default-1379008976281\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - prefs.js: keyword.URL -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-vProt - c:\program files\AVG SafeGuard toolbar\vprot.exe
AddRemove-AVG SafeGuard toolbar - c:\program files\AVG SafeGuard toolbar\UNINSTALL.exe
AddRemove-Delta Chrome Toolbar - c:\documents and settings\Sett\Data aplikací\BabSolution\Shared\GUninstaller.exe
AddRemove-Tzar - c:\windows\IsUn0405.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-04-28 13:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1715567821-308236825-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1715567821-308236825-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:81,11,3a,ee,df,57,bb,c2,06,a9,c0,9e,95,eb,78,15,9d,0d,f0,52,42,90,bd,
53,0a,e3,00,b4,1c,49,91,1e,04,de,f8,f4,c8,44,40,73,46,30,87,76,1c,7b,a9,19,\
"??"=hex:72,ef,cb,f5,29,a2,69,2d,86,bf,b4,a5,52,fe,53,f6
.
[HKEY_USERS\S-1-5-21-1715567821-308236825-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:f9,6b,98,d9,0b,11,16,09,96,79,da,f7,ec,f3,d8,e7,8f,78,0d,eb,75,
11,cd,63,31,d0,1a,c9,47,bb,41,65,78,5c,0a,35,ec,45,2c,c8,5c,cb,ff,e9,0a,da,\
"rkeysecu"=hex:17,25,b9,75,ca,61,49,35,79,c3,11,51,05,be,89,f5
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\N*e*e*d* *F*o*r* *S*p*e*e*d* *W*o*r*l*d* *S*i*t*e*"!\NFS Most Wanted Cop Hummer H3 Mod]
"Install Dir"="c:\\Documents and Settings\\Sett\\Plocha\\NFS\\Need For Speed - Most Wanted"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1108)
c:\windows\system32\CLBCATQ.DLL
.
- - - - - - - > 'explorer.exe'(1368)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\RTHDCPL.EXE
c:\program files\Gaming Keyboard\OSD.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\program files\Sony\Sony PC Companion\PCCompanionInfo.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
c:\program files\Sony\Sony PC Companion\Drivers\DPInst.exe
.
**************************************************************************
.
Celkový čas: 2014-04-28 13:32:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-04-28 11:32
.
Před spuštěním: Volných bajtů: 26 196 713 472
Po spuštění: Volných bajtů: 26 366 242 816
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 222D93CF5EE623FE4CAA9738E93B3E7B
413FC2A0C716421B3158746D63736515
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3070.1914 [GMT 2:00]
Spuštěný z: c:\documents and settings\Sett\Plocha\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Data aplikací\HirezPipeError.txt
c:\documents and settings\Sett\WINDOWS
C:\END
c:\windows\IsUn0405.exe
c:\windows\Readme.txt
c:\windows\system32\Cache
c:\windows\system32\Cache\05b3566814c1c2ec.fb
c:\windows\system32\Cache\075884af680ff6dc.fb
c:\windows\system32\Cache\106510aea847404a.fb
c:\windows\system32\Cache\17cae453d65bd7d5.fb
c:\windows\system32\Cache\227113dfa1ca894d.fb
c:\windows\system32\Cache\26c630d098e22dd5.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\2efed7725b9c9b79.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\332f5cf92a2acb12.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\3d0c20e52984bab4.fb
c:\windows\system32\Cache\450d477ff55871e4.fb
c:\windows\system32\Cache\49fbbc5a8678d502.fb
c:\windows\system32\Cache\57b8735085c2d402.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\5da898cfcc3a7e94.fb
c:\windows\system32\Cache\5f792de28eabf493.fb
c:\windows\system32\Cache\5fe642af980d0463.fb
c:\windows\system32\Cache\601fcb27b6af3e27.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\613e8ce7ab7106af.fb
c:\windows\system32\Cache\633a76311867bd11.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\691f14230153a9e1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6cb409d7ac73d9f1.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\7614bd6cfa99e546.fb
c:\windows\system32\Cache\77664b6ccc36be9f.fb
c:\windows\system32\Cache\77a63fce52270c47.fb
c:\windows\system32\Cache\881b3593316772f0.fb
c:\windows\system32\Cache\895b0fa307ac2927.fb
c:\windows\system32\Cache\95f567698be8a182.fb
c:\windows\system32\Cache\98657d0579ae1930.fb
c:\windows\system32\Cache\a0fe2528705655a0.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\ad92d44a8edfad97.fb
c:\windows\system32\Cache\b9040adb9f0fae54.fb
c:\windows\system32\Cache\bf0ef6c221611fc4.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\cdf4b759b4266804.fb
c:\windows\system32\Cache\cec006b864adbfa2.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d5c0f4e7bbe35bf3.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\d9ca663388d21ec0.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\f2cda51fd108941f.fb
c:\windows\system32\Cache\f34d8db84131d925.fb
c:\windows\system32\Cache\f469d1e5b4a9e1a7.fb
c:\windows\system32\Cache\f814b42f6b1e3213.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\Oleaut32.1
c:\windows\system32\SET268.tmp
c:\windows\system32\SET26D.tmp
c:\windows\system32\x.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_WSYSSVC
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-28 do 2014-04-28 )))))))))))))))))))))))))))))))
.
.
2014-04-27 08:40 . 2014-04-27 08:40 -------- d-----w- c:\documents and settings\Sett\Data aplikací\Malwarebytes
2014-04-27 08:39 . 2014-04-27 08:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2014-04-26 22:41 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-04-26 21:22 . 2014-04-26 21:26 -------- d-----w- c:\program files\trend micro
2014-04-26 21:22 . 2014-04-26 21:26 -------- d-----w- C:\rsit
2014-04-19 23:27 . 2014-04-19 23:29 -------- d-----w- c:\documents and settings\Sett\Data aplikací\deluge
2014-04-07 19:22 . 2014-04-07 19:22 -------- d-----w- c:\documents and settings\Sett\Data aplikací\Awesomium
2014-04-07 19:21 . 2014-04-07 19:21 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Hi-Rez Studios
2014-04-06 00:31 . 2013-06-28 09:44 27776 ----a-w- c:\windows\system32\drivers\lgandnetmodem.sys
2014-04-06 00:31 . 2013-04-18 14:09 23168 ----a-w- c:\windows\system32\drivers\lgandnetdiag.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-18 13:02 . 2011-12-23 11:32 199960 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-03-31 14:11 . 2010-11-12 12:19 211224 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-03-31 14:11 . 2010-09-07 02:48 108312 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2014-03-27 20:15 . 2010-12-08 03:12 193304 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-03-27 20:14 . 2013-08-01 14:06 123160 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-03-27 20:04 . 2012-04-19 02:50 150296 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-03-27 20:04 . 2013-02-08 02:37 238872 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-03-27 20:03 . 2010-09-07 02:48 28440 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-03-27 20:03 . 2011-12-23 11:32 22296 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
2014-03-21 15:57 . 2014-01-30 11:42 42272 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-03-12 13:33 . 2012-04-08 17:17 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 13:33 . 2012-03-14 05:20 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-12 13:33 . 2014-02-21 16:33 5777288 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-02-07 17:24 . 2014-02-07 16:43 94336 ----a-w- c:\windows\system32\drivers\IT9135BDA.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony PC Companion"="c:\program files\Sony\Sony PC Companion\PCCompanion.exe" [2013-10-31 449760]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-26 19522592]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-09-04 767312]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-10-19 1983816]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-04-06 5180432]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"VICTORY Gaming Keyboard"="c:\program files\Gaming Keyboard\Monitor.exe" [2013-04-09 270336]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"Printsrv"="c:\windows\System32\Printing_Admin_Scripts\en-US\drvupd.vbs" [2014-01-11 579]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2014\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamersFirst LIVE!.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\GamersFirst LIVE!.lnk
backup=c:\windows\pss\GamersFirst LIVE!.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena Messenger\\Room\\garena_room.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\Sett\\Plocha\\NFS\\Need For Speed - Most Wanted\\Speed.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Games\\Warcraft III\\Warcraft III.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\java.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer_Service.exe"=
"c:\\Games\\Northland\\Game.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"c:\\Documents and Settings\\Sett\\Data aplikací\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Garena Messenger\\ggdllhost.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgmfapx.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2014\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"58090:TCP"= 58090:TCP:Pando Media Booster
"58090:UDP"= 58090:UDP:Pando Media Booster
"58866:TCP"= 58866:TCP:Pando Media Booster
"58866:UDP"= 58866:UDP:Pando Media Booster
"22:TCP"= 22:TCP:192.168.0.120/255.255.255.255:Enabled:Sivi_PC
"57267:TCP"= 57267:TCP:Pando Media Booster
"57267:UDP"= 57267:UDP:Pando Media Booster
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [19.4.2012 4:50 150296]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [8.2.2013 4:37 238872]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7.9.2010 4:48 28440]
R1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [1.8.2013 16:06 123160]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [23.12.2011 13:32 199960]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [23.12.2011 13:32 22296]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [8.12.2010 5:12 193304]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [12.11.2010 14:19 211224]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [30.1.2014 13:42 42272]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [30.10.2013 12:34 203024]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [30.10.2013 12:34 103696]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2014\avgidsagent.exe [18.4.2014 15:22 3645456]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2014\avgwdsvc.exe [27.3.2014 22:10 291912]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\games\SMITE\HiPatchService.exe [7.4.2014 21:21 9216]
R2 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [15.7.2007 4:37 27992]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [9.10.2013 10:58 3275136]
R2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [4.3.2013 23:06 3560800]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [17.4.2013 15:11 242240]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [28.4.2011 21:19 44032]
R3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2.8.2012 12:53 155824]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\drivers\VBoxNetFlt.sys [15.10.2013 14:42 126224]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [23.10.2013 9:15 172192]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [28.4.2011 21:17 1691480]
S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys [6.4.2014 2:31 23168]
S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys [6.4.2014 2:31 27776]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [21.6.2012 20:41 112640]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2.8.2012 12:55 12400]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Messenger\Room\safedrv.sys --> c:\program files\Garena Messenger\Room\safedrv.sys [?]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [7.8.2012 9:37 100480]
S3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\drivers\IT9135BDA.sys [7.2.2014 18:43 94336]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [10.5.2013 21:52 25088]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [15.10.2013 14:42 114960]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - SONY_PC_COMPANION
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-26 03:19 1078088 ----a-w- c:\program files\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 13:33]
.
2014-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-26 13:54]
.
2014-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-26 13:54]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.10.10.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Sett\Data aplikací\Mozilla\Firefox\Profiles\d103pnm3.default-1379008976281\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - prefs.js: keyword.URL -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-vProt - c:\program files\AVG SafeGuard toolbar\vprot.exe
AddRemove-AVG SafeGuard toolbar - c:\program files\AVG SafeGuard toolbar\UNINSTALL.exe
AddRemove-Delta Chrome Toolbar - c:\documents and settings\Sett\Data aplikací\BabSolution\Shared\GUninstaller.exe
AddRemove-Tzar - c:\windows\IsUn0405.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-04-28 13:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1715567821-308236825-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1715567821-308236825-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:81,11,3a,ee,df,57,bb,c2,06,a9,c0,9e,95,eb,78,15,9d,0d,f0,52,42,90,bd,
53,0a,e3,00,b4,1c,49,91,1e,04,de,f8,f4,c8,44,40,73,46,30,87,76,1c,7b,a9,19,\
"??"=hex:72,ef,cb,f5,29,a2,69,2d,86,bf,b4,a5,52,fe,53,f6
.
[HKEY_USERS\S-1-5-21-1715567821-308236825-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:f9,6b,98,d9,0b,11,16,09,96,79,da,f7,ec,f3,d8,e7,8f,78,0d,eb,75,
11,cd,63,31,d0,1a,c9,47,bb,41,65,78,5c,0a,35,ec,45,2c,c8,5c,cb,ff,e9,0a,da,\
"rkeysecu"=hex:17,25,b9,75,ca,61,49,35,79,c3,11,51,05,be,89,f5
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\N*e*e*d* *F*o*r* *S*p*e*e*d* *W*o*r*l*d* *S*i*t*e*"!\NFS Most Wanted Cop Hummer H3 Mod]
"Install Dir"="c:\\Documents and Settings\\Sett\\Plocha\\NFS\\Need For Speed - Most Wanted"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1108)
c:\windows\system32\CLBCATQ.DLL
.
- - - - - - - > 'explorer.exe'(1368)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\RTHDCPL.EXE
c:\program files\Gaming Keyboard\OSD.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\program files\Sony\Sony PC Companion\PCCompanionInfo.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
c:\program files\Sony\Sony PC Companion\Drivers\DPInst.exe
.
**************************************************************************
.
Celkový čas: 2014-04-28 13:32:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-04-28 11:32
.
Před spuštěním: Volných bajtů: 26 196 713 472
Po spuštění: Volných bajtů: 26 366 242 816
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 222D93CF5EE623FE4CAA9738E93B3E7B
413FC2A0C716421B3158746D63736515