Re: RSIT preventivka - pomalý počítač
Napsal: 26 črc 2015 08:50
ComboFix 15-07-23.01 - planeo 26.07.2015 9:40.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2986.2026 [GMT 2:00]
Spuštěný z: c:\users\planeo\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\01_05_2013.scr
c:\windows\system32\06_03_2013.scr
c:\windows\system32\17_04_2013.scr
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-06-26 do 2015-07-26 )))))))))))))))))))))))))))))))
.
.
2015-07-26 07:47 . 2015-07-26 07:47 -------- d-----w- c:\users\planeo\AppData\Local\temp
2015-07-26 07:47 . 2015-07-26 07:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-07-25 07:26 . 2015-07-25 19:40 -------- d-----w- C:\FRST
2015-07-23 05:14 . 2015-07-23 05:09 313472 ----a-w- c:\windows\system32\aswBoot.exe
2015-07-23 05:09 . 2015-07-23 05:09 43112 ----a-w- c:\windows\avastSS.scr
2015-07-22 16:47 . 2015-07-22 16:49 -------- d-----w- C:\AdwCleaner
2015-07-22 14:33 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{91BA8942-D175-4F22-A091-7C99CB5D3AAE}\mpengine.dll
2015-07-22 14:32 . 2015-07-15 02:55 26624 ----a-w- c:\windows\system32\lpk.dll
2015-07-22 14:32 . 2015-07-15 02:55 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-07-22 14:32 . 2015-07-15 02:55 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-07-22 14:32 . 2015-07-15 02:55 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-07-22 14:32 . 2015-07-15 01:52 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-07-22 14:09 . 2014-11-11 11:32 24184 ----a-w- c:\windows\system32\drivers\asw409B.tmp
2015-07-22 12:05 . 2015-07-25 07:19 -------- d-----w- c:\program files\trend micro
2015-07-22 12:05 . 2015-07-22 12:20 -------- d-----w- C:\rsit
2015-07-18 21:09 . 2015-07-18 21:09 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-07-18 21:09 . 2015-07-22 14:17 -------- d-----w- c:\program files\Java
2015-07-15 04:56 . 2015-07-04 17:48 1414656 ----a-w- c:\windows\system32\ole32.dll
2015-07-15 04:55 . 2015-06-19 18:31 37888 ----a-w- c:\program files\Internet Explorer\DiagnosticsHub_is.dll
2015-07-06 12:18 . 2015-07-06 12:18 -------- d-----w- c:\program files\Rockstar Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-23 05:14 . 2013-12-21 08:13 113592 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-07-23 05:14 . 2013-05-11 08:55 208664 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-07-23 05:14 . 2013-05-11 08:55 433264 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-07-23 05:14 . 2013-05-11 08:55 49776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-07-23 05:14 . 2013-05-11 08:55 76000 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-07-23 05:14 . 2014-05-11 05:32 24016 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-07-23 05:14 . 2013-05-11 08:55 81728 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-07-23 05:08 . 2013-05-11 08:55 788784 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-07-15 10:02 . 2013-05-11 10:26 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-07-15 10:02 . 2011-12-29 08:35 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-07-01 20:30 . 2015-07-15 04:57 248832 ----a-w- c:\windows\system32\schannel.dll
2015-06-23 11:27 . 2011-12-28 12:09 246952 ------w- c:\windows\system32\MpSigStub.exe
2015-05-25 18:07 . 2015-06-10 11:29 3989440 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-05-25 18:07 . 2015-06-10 11:29 3934144 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-05-25 18:04 . 2015-06-10 11:29 1307648 ----a-w- c:\windows\system32\ntdll.dll
2015-05-25 18:01 . 2015-06-10 11:29 853504 ----a-w- c:\windows\system32\diagtrack.dll
2015-05-25 18:01 . 2015-06-10 11:29 635392 ----a-w- c:\windows\system32\tdh.dll
2015-05-25 18:01 . 2015-06-10 11:29 400896 ----a-w- c:\windows\system32\srcore.dll
2015-05-25 18:01 . 2015-06-10 11:28 43008 ----a-w- c:\windows\system32\srclient.dll
2015-05-25 18:01 . 2015-06-10 11:29 92160 ----a-w- c:\windows\system32\sechost.dll
2015-05-25 18:01 . 2015-06-10 11:28 38912 ----a-w- c:\windows\system32\csrsrv.dll
2015-05-25 18:01 . 2015-06-10 11:29 641536 ----a-w- c:\windows\system32\advapi32.dll
2015-05-25 18:00 . 2015-06-10 11:28 40448 ----a-w- c:\windows\system32\typeperf.exe
2015-05-25 18:00 . 2015-06-10 11:29 364544 ----a-w- c:\windows\system32\tracerpt.exe
2015-05-25 18:00 . 2015-06-10 11:28 69632 ----a-w- c:\windows\system32\smss.exe
2015-05-25 18:00 . 2015-06-10 11:29 262656 ----a-w- c:\windows\system32\rstrui.exe
2015-05-25 18:00 . 2015-06-10 11:28 37888 ----a-w- c:\windows\system32\relog.exe
2015-05-25 18:00 . 2015-06-10 11:29 82944 ----a-w- c:\windows\system32\logman.exe
2015-05-25 18:00 . 2015-06-10 11:28 17408 ----a-w- c:\windows\system32\diskperf.exe
2015-05-25 17:55 . 2015-06-10 11:28 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-05-25 16:53 . 2015-06-10 11:28 36864 ----a-w- c:\windows\system32\UtcResources.dll
2015-05-21 13:20 . 2015-06-10 11:30 163840 ----a-w- c:\windows\system32\aepic.dll
2015-05-09 03:14 . 2015-06-10 11:28 169984 ----a-w- c:\windows\system32\winsrv.dll
2015-05-09 03:13 . 2015-06-10 11:28 293376 ----a-w- c:\windows\system32\KernelBase.dll
2015-05-09 03:12 . 2015-06-10 11:28 271360 ----a-w- c:\windows\system32\conhost.exe
2015-05-09 03:08 . 2015-06-10 11:28 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-01 13:16 . 2015-05-13 19:44 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-04-29 18:07 . 2015-06-10 11:28 4096 ----a-w- c:\windows\system32\msdxm.ocx
2015-04-29 18:07 . 2015-06-10 11:28 4096 ----a-w- c:\windows\system32\dxmasf.dll
2015-04-29 18:07 . 2015-06-10 11:28 8192 ----a-w- c:\windows\system32\spwmp.dll
2015-04-29 18:05 . 2015-06-10 11:28 12625408 ----a-w- c:\windows\system32\wmploc.DLL
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-07-23 05:08 692512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2013-02-04 894344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2011-06-24 3770480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 146032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 181360]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 190064]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-07-23 6109776]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2013-02-04 894344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2015-07-23 113592]
R3 cpuz134;cpuz134;c:\users\planeo\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-06-19 102912]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-28 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2015-07-23 788784]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2015-07-23 433264]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2015-07-23 24016]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2015-07-23 76000]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 mitsijm2014;Správce úloh aplikace Autodesk Simulation Moldflow MITSI 2014;c:\program files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe [2013-01-25 723744]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2011-06-14 27760]
S3 L1c;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\l1c51x86.sys [2010-10-21 62576]
S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECI.sys [2010-10-19 41088]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2011-06-14 1806448]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
utcsvc REG_MULTI_SZ DiagTrack
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-07-25 19:43 995144 ----a-w- c:\program files\Google\Chrome\Application\44.0.2403.107\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
uStart Page = https://www.seznam.cz/
mStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 84.16.113.2 84.16.96.2 84.16.113.105
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2015-07-26 09:48:18
ComboFix-quarantined-files.txt 2015-07-26 07:48
.
Před spuštěním: Volných bajtů: 165 516 808 192
Po spuštění: Volných bajtů: 165 416 394 752
.
- - End Of File - - B1085AF0E1D88A7A5DF0BB8E655364B9
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2986.2026 [GMT 2:00]
Spuštěný z: c:\users\planeo\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\01_05_2013.scr
c:\windows\system32\06_03_2013.scr
c:\windows\system32\17_04_2013.scr
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-06-26 do 2015-07-26 )))))))))))))))))))))))))))))))
.
.
2015-07-26 07:47 . 2015-07-26 07:47 -------- d-----w- c:\users\planeo\AppData\Local\temp
2015-07-26 07:47 . 2015-07-26 07:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-07-25 07:26 . 2015-07-25 19:40 -------- d-----w- C:\FRST
2015-07-23 05:14 . 2015-07-23 05:09 313472 ----a-w- c:\windows\system32\aswBoot.exe
2015-07-23 05:09 . 2015-07-23 05:09 43112 ----a-w- c:\windows\avastSS.scr
2015-07-22 16:47 . 2015-07-22 16:49 -------- d-----w- C:\AdwCleaner
2015-07-22 14:33 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{91BA8942-D175-4F22-A091-7C99CB5D3AAE}\mpengine.dll
2015-07-22 14:32 . 2015-07-15 02:55 26624 ----a-w- c:\windows\system32\lpk.dll
2015-07-22 14:32 . 2015-07-15 02:55 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-07-22 14:32 . 2015-07-15 02:55 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-07-22 14:32 . 2015-07-15 02:55 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-07-22 14:32 . 2015-07-15 01:52 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-07-22 14:09 . 2014-11-11 11:32 24184 ----a-w- c:\windows\system32\drivers\asw409B.tmp
2015-07-22 12:05 . 2015-07-25 07:19 -------- d-----w- c:\program files\trend micro
2015-07-22 12:05 . 2015-07-22 12:20 -------- d-----w- C:\rsit
2015-07-18 21:09 . 2015-07-18 21:09 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-07-18 21:09 . 2015-07-22 14:17 -------- d-----w- c:\program files\Java
2015-07-15 04:56 . 2015-07-04 17:48 1414656 ----a-w- c:\windows\system32\ole32.dll
2015-07-15 04:55 . 2015-06-19 18:31 37888 ----a-w- c:\program files\Internet Explorer\DiagnosticsHub_is.dll
2015-07-06 12:18 . 2015-07-06 12:18 -------- d-----w- c:\program files\Rockstar Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-23 05:14 . 2013-12-21 08:13 113592 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-07-23 05:14 . 2013-05-11 08:55 208664 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-07-23 05:14 . 2013-05-11 08:55 433264 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-07-23 05:14 . 2013-05-11 08:55 49776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-07-23 05:14 . 2013-05-11 08:55 76000 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-07-23 05:14 . 2014-05-11 05:32 24016 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-07-23 05:14 . 2013-05-11 08:55 81728 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-07-23 05:08 . 2013-05-11 08:55 788784 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-07-15 10:02 . 2013-05-11 10:26 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-07-15 10:02 . 2011-12-29 08:35 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-07-01 20:30 . 2015-07-15 04:57 248832 ----a-w- c:\windows\system32\schannel.dll
2015-06-23 11:27 . 2011-12-28 12:09 246952 ------w- c:\windows\system32\MpSigStub.exe
2015-05-25 18:07 . 2015-06-10 11:29 3989440 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-05-25 18:07 . 2015-06-10 11:29 3934144 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-05-25 18:04 . 2015-06-10 11:29 1307648 ----a-w- c:\windows\system32\ntdll.dll
2015-05-25 18:01 . 2015-06-10 11:29 853504 ----a-w- c:\windows\system32\diagtrack.dll
2015-05-25 18:01 . 2015-06-10 11:29 635392 ----a-w- c:\windows\system32\tdh.dll
2015-05-25 18:01 . 2015-06-10 11:29 400896 ----a-w- c:\windows\system32\srcore.dll
2015-05-25 18:01 . 2015-06-10 11:28 43008 ----a-w- c:\windows\system32\srclient.dll
2015-05-25 18:01 . 2015-06-10 11:29 92160 ----a-w- c:\windows\system32\sechost.dll
2015-05-25 18:01 . 2015-06-10 11:28 38912 ----a-w- c:\windows\system32\csrsrv.dll
2015-05-25 18:01 . 2015-06-10 11:29 641536 ----a-w- c:\windows\system32\advapi32.dll
2015-05-25 18:00 . 2015-06-10 11:28 40448 ----a-w- c:\windows\system32\typeperf.exe
2015-05-25 18:00 . 2015-06-10 11:29 364544 ----a-w- c:\windows\system32\tracerpt.exe
2015-05-25 18:00 . 2015-06-10 11:28 69632 ----a-w- c:\windows\system32\smss.exe
2015-05-25 18:00 . 2015-06-10 11:29 262656 ----a-w- c:\windows\system32\rstrui.exe
2015-05-25 18:00 . 2015-06-10 11:28 37888 ----a-w- c:\windows\system32\relog.exe
2015-05-25 18:00 . 2015-06-10 11:29 82944 ----a-w- c:\windows\system32\logman.exe
2015-05-25 18:00 . 2015-06-10 11:28 17408 ----a-w- c:\windows\system32\diskperf.exe
2015-05-25 17:55 . 2015-06-10 11:28 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-05-25 16:53 . 2015-06-10 11:28 36864 ----a-w- c:\windows\system32\UtcResources.dll
2015-05-21 13:20 . 2015-06-10 11:30 163840 ----a-w- c:\windows\system32\aepic.dll
2015-05-09 03:14 . 2015-06-10 11:28 169984 ----a-w- c:\windows\system32\winsrv.dll
2015-05-09 03:13 . 2015-06-10 11:28 293376 ----a-w- c:\windows\system32\KernelBase.dll
2015-05-09 03:12 . 2015-06-10 11:28 271360 ----a-w- c:\windows\system32\conhost.exe
2015-05-09 03:08 . 2015-06-10 11:28 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-09 03:08 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-09 01:59 . 2015-06-10 11:28 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-01 13:16 . 2015-05-13 19:44 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-04-29 18:07 . 2015-06-10 11:28 4096 ----a-w- c:\windows\system32\msdxm.ocx
2015-04-29 18:07 . 2015-06-10 11:28 4096 ----a-w- c:\windows\system32\dxmasf.dll
2015-04-29 18:07 . 2015-06-10 11:28 8192 ----a-w- c:\windows\system32\spwmp.dll
2015-04-29 18:05 . 2015-06-10 11:28 12625408 ----a-w- c:\windows\system32\wmploc.DLL
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-07-23 05:08 692512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2013-02-04 894344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2011-06-24 3770480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 146032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 181360]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 190064]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-07-23 6109776]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2013-02-04 894344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2015-07-23 113592]
R3 cpuz134;cpuz134;c:\users\planeo\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-06-19 102912]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-28 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2015-07-23 788784]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2015-07-23 433264]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2015-07-23 24016]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2015-07-23 76000]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 mitsijm2014;Správce úloh aplikace Autodesk Simulation Moldflow MITSI 2014;c:\program files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe [2013-01-25 723744]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2011-06-14 27760]
S3 L1c;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\l1c51x86.sys [2010-10-21 62576]
S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECI.sys [2010-10-19 41088]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2011-06-14 1806448]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
utcsvc REG_MULTI_SZ DiagTrack
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-07-25 19:43 995144 ----a-w- c:\program files\Google\Chrome\Application\44.0.2403.107\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
uStart Page = https://www.seznam.cz/
mStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 84.16.113.2 84.16.96.2 84.16.113.105
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2015-07-26 09:48:18
ComboFix-quarantined-files.txt 2015-07-26 07:48
.
Před spuštěním: Volných bajtů: 165 516 808 192
Po spuštění: Volných bajtů: 165 416 394 752
.
- - End Of File - - B1085AF0E1D88A7A5DF0BB8E655364B9
A36C5E4F47E84449FF07ED3517B43A31