Re: Pocitac ide pomaly no nie je vytazeny
Napsal: 08 srp 2015 11:07
ComboFix 15-08-06.01 - diviak . 08. 2015 11:45:18.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.3037.1600 [GMT 2:00]
Running from: c:\users\diviak\Desktop\ComboFix.exe
Command switches used :: c:\users\diviak\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cd607a4c9a22cb.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1ca30d04c6389b8.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf523bb685f195.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf6b9aa7cc50e2.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d02f4d4204f075.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d043071fb3c688.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d0bff068180956.job"
"c:\windows\Tasks\Norton Security Scan for diviak.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\McAfee Security Scan
c:\program files\McAfee Security Scan\3.11.149\AVScanComponent.dll
c:\program files\McAfee Security Scan\3.11.149\AVScanner.ini
c:\program files\McAfee Security Scan\3.11.149\avvclean.dat
c:\program files\McAfee Security Scan\3.11.149\avvnames.dat
c:\program files\McAfee Security Scan\3.11.149\avvscan.dat
c:\program files\McAfee Security Scan\3.11.149\config.dat
c:\program files\McAfee Security Scan\3.11.149\ftconfig.ini
c:\program files\McAfee Security Scan\3.11.149\McAfee.ico
c:\program files\McAfee Security Scan\3.11.149\mcbrwsr2.dll
c:\program files\McAfee Security Scan\3.11.149\MCCompHostConfig.ini
c:\program files\McAfee Security Scan\3.11.149\McCHSvc.exe
c:\program files\McAfee Security Scan\3.11.149\McInstallerRes.dll
c:\program files\McAfee Security Scan\3.11.149\McInstallerRes_LD.dll
c:\program files\McAfee Security Scan\3.11.149\McInstallerStartup.dll
c:\program files\McAfee Security Scan\3.11.149\mcscan32.dll
c:\program files\McAfee Security Scan\3.11.149\McUICnt.exe
c:\program files\McAfee Security Scan\3.11.149\McUpdater.dll
c:\program files\McAfee Security Scan\3.11.149\sa_cache_sqlite.dll
c:\program files\McAfee Security Scan\3.11.149\sa_http_win32.dll
c:\program files\McAfee Security Scan\3.11.149\sa_mbl.dll
c:\program files\McAfee Security Scan\3.11.149\sa_store_sqlite.dll
c:\program files\McAfee Security Scan\3.11.149\sacore.db
c:\program files\McAfee Security Scan\3.11.149\sacore.dll
c:\program files\McAfee Security Scan\3.11.149\sacoredata\uds_filetypes.txt
c:\program files\McAfee Security Scan\3.11.149\sacoredata\uds_hosting.txt
c:\program files\McAfee Security Scan\3.11.149\sacoredata\uds_tlds.txt
c:\program files\McAfee Security Scan\3.11.149\SecurityScanner.dll
c:\program files\McAfee Security Scan\3.11.149\SecurityScanner_LD.dll
c:\program files\McAfee Security Scan\3.11.149\signlic.txt
c:\program files\McAfee Security Scan\3.11.149\sqlite3.dll
c:\program files\McAfee Security Scan\3.11.149\SSScheduler.exe
c:\program files\McAfee Security Scan\3.11.149\uninstaller.ini
c:\program files\McAfee Security Scan\3.11.149\WebInfoScanner.dll
c:\program files\McAfee Security Scan\3.11.149\WMIScanner.dll
c:\program files\McAfee Security Scan\uninstall.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_BBSvc
-------\Service_BBUpdate
-------\Service_McComponentHostService
.
.
((((((((((((((((((((((((( Files Created from 2015-07-08 to 2015-08-08 )))))))))))))))))))))))))))))))
.
.
2015-08-07 14:21 . 2015-08-07 14:21 -------- d-----w- c:\users\diviak\AppData\Roaming\HD Tune Pro
2015-08-07 14:21 . 2015-08-07 14:21 -------- d-----w- c:\program files\HD Tune Pro
2015-08-07 14:14 . 2015-08-07 14:14 -------- d-----w- c:\windows\system32\wbem\Framework
2015-08-07 14:14 . 2015-08-07 14:14 39168 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\MpKsle6033213.sys
2015-08-07 12:38 . 2015-08-07 12:38 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\offreg.804.dll
2015-08-07 09:08 . 2015-07-01 14:41 912000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A4043178-625C-43D8-822A-89BBCC57B46D}\gapaengine.dll
2015-08-07 09:05 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\mpengine.dll
2015-08-06 20:13 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-08-06 09:48 . 2015-08-07 12:39 98520 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-06 09:47 . 2015-08-06 09:47 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-08-06 09:47 . 2015-08-06 09:47 -------- d-----w- c:\programdata\Malwarebytes
2015-08-06 09:47 . 2015-06-18 06:41 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-08-06 09:47 . 2015-06-18 06:41 94936 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-08-06 09:47 . 2015-06-18 06:41 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-08-06 09:31 . 2015-08-07 08:55 -------- d-----w- C:\AdwCleaner
2015-08-05 08:52 . 2015-08-05 08:53 -------- d-----w- C:\rsit
2015-08-05 08:52 . 2015-08-05 08:52 -------- d-----w- c:\program files\trend micro
2015-07-29 05:23 . 2015-07-25 17:47 587264 ----a-w- c:\windows\system32\generaltel.dll
2015-07-29 05:23 . 2015-07-25 17:47 628736 ----a-w- c:\windows\system32\invagent.dll
2015-07-29 05:23 . 2015-07-25 17:46 342016 ----a-w- c:\windows\system32\devinv.dll
2015-07-29 05:23 . 2015-07-25 17:46 924160 ----a-w- c:\windows\system32\appraiser.dll
2015-07-29 05:23 . 2015-07-25 17:46 58880 ----a-w- c:\windows\system32\acmigration.dll
2015-07-29 05:23 . 2015-07-25 17:40 932864 ----a-w- c:\windows\system32\aeinv.dll
2015-07-29 05:23 . 2015-07-25 17:51 15808 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-07-29 05:23 . 2015-07-25 17:46 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-07-21 15:31 . 2015-07-15 02:55 26624 ----a-w- c:\windows\system32\lpk.dll
2015-07-21 15:31 . 2015-07-15 02:55 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-07-21 15:31 . 2015-07-15 02:55 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-07-21 15:31 . 2015-07-15 02:55 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-07-21 15:31 . 2015-07-15 01:52 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-07-16 18:37 . 2015-06-15 21:47 101824 ----a-w- c:\windows\system32\consent.exe
2015-07-16 18:37 . 2015-06-15 21:43 2364416 ----a-w- c:\windows\system32\msi.dll
2015-07-16 18:37 . 2015-06-15 21:43 1805824 ----a-w- c:\windows\system32\authui.dll
2015-07-16 18:37 . 2015-06-15 21:43 337408 ----a-w- c:\windows\system32\msihnd.dll
2015-07-16 18:37 . 2015-06-15 21:43 47104 ----a-w- c:\windows\system32\appinfo.dll
2015-07-16 18:37 . 2015-06-15 21:42 73216 ----a-w- c:\windows\system32\msiexec.exe
2015-07-16 18:37 . 2015-06-15 21:37 25088 ----a-w- c:\windows\system32\msimsg.dll
2015-07-15 20:57 . 2015-06-25 08:46 2383872 ----a-w- c:\windows\system32\win32k.sys
2015-07-15 20:55 . 2015-07-04 17:48 1414656 ----a-w- c:\windows\system32\ole32.dll
2015-07-15 20:55 . 2015-06-17 17:39 305664 ----a-w- c:\windows\system32\gdi32.dll
2015-07-15 20:55 . 2015-04-27 19:04 143872 ----a-w- c:\windows\system32\cryptsvc.dll
2015-07-15 20:55 . 2015-04-27 19:04 1174528 ----a-w- c:\windows\system32\crypt32.dll
2015-07-15 20:55 . 2015-04-27 19:05 179200 ----a-w- c:\windows\system32\wintrust.dll
2015-07-15 20:55 . 2015-04-27 19:04 103936 ----a-w- c:\windows\system32\cryptnet.dll
2015-07-15 20:44 . 2015-06-19 18:31 37888 ----a-w- c:\program files\Internet Explorer\DiagnosticsHub_is.dll
2015-07-15 20:43 . 2015-06-19 17:53 817664 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2015-07-15 20:43 . 2015-06-19 18:25 504320 ----a-w- c:\windows\system32\vbscript.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-05 10:11 . 2011-05-08 13:10 246952 ------w- c:\windows\system32\MpSigStub.exe
2015-07-01 20:30 . 2015-07-15 20:56 248832 ----a-w- c:\windows\system32\schannel.dll
2015-07-01 14:41 . 2011-05-26 06:04 912000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2015-06-16 23:01 . 2015-06-16 23:01 1202856 ----a-w- c:\windows\system32\FM20.DLL
2015-05-25 18:07 . 2015-06-10 07:07 3989440 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-05-25 18:07 . 2015-06-10 07:07 3934144 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-05-25 18:04 . 2015-06-10 07:07 1307648 ----a-w- c:\windows\system32\ntdll.dll
2015-05-25 18:01 . 2015-06-10 07:07 853504 ----a-w- c:\windows\system32\diagtrack.dll
2015-05-25 18:01 . 2015-06-10 07:06 635392 ----a-w- c:\windows\system32\tdh.dll
2015-05-25 18:01 . 2015-06-10 07:07 400896 ----a-w- c:\windows\system32\srcore.dll
2015-05-25 18:01 . 2015-06-10 07:06 43008 ----a-w- c:\windows\system32\srclient.dll
2015-05-25 18:01 . 2015-06-10 07:06 92160 ----a-w- c:\windows\system32\sechost.dll
2015-05-25 18:01 . 2015-06-10 07:06 38912 ----a-w- c:\windows\system32\csrsrv.dll
2015-05-25 18:01 . 2015-06-10 07:07 641536 ----a-w- c:\windows\system32\advapi32.dll
2015-05-25 18:00 . 2015-06-10 07:06 40448 ----a-w- c:\windows\system32\typeperf.exe
2015-05-25 18:00 . 2015-06-10 07:07 364544 ----a-w- c:\windows\system32\tracerpt.exe
2015-05-25 18:00 . 2015-06-10 07:06 69632 ----a-w- c:\windows\system32\smss.exe
2015-05-25 18:00 . 2015-06-10 07:07 262656 ----a-w- c:\windows\system32\rstrui.exe
2015-05-25 18:00 . 2015-06-10 07:06 37888 ----a-w- c:\windows\system32\relog.exe
2015-05-25 18:00 . 2015-06-10 07:07 82944 ----a-w- c:\windows\system32\logman.exe
2015-05-25 18:00 . 2015-06-10 07:06 17408 ----a-w- c:\windows\system32\diskperf.exe
2015-05-25 17:55 . 2015-06-10 07:06 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-05-25 16:53 . 2015-06-10 07:06 36864 ----a-w- c:\windows\system32\UtcResources.dll
2015-05-21 13:20 . 2015-06-10 07:08 163840 ----a-w- c:\windows\system32\aepic.dll
2006-06-15 18:33 . 2011-05-10 22:23 233472 ----a-w- c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-25 16:43 . 2011-05-10 22:23 204895 ----a-w- c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 12:41 . 2011-05-10 22:23 77824 ----a-w- c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2006-06-19 11:10 . 2011-05-10 22:23 426081 ----a-w- c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 10:19 . 2011-05-10 22:23 458752 ----a-w- c:\program files\mozilla firefox\plugins\imagickrt.dll
2006-04-10 16:35 . 2011-05-10 22:23 139264 ----a-w- c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 09:10 . 2011-05-10 22:23 204800 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 09:42 . 2011-05-10 22:23 106496 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 09:22 . 2011-05-10 22:23 212992 ----a-w- c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 09:21 . 2011-05-10 22:23 167936 ----a-w- c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
2011-03-18 18:05 . 2011-05-08 13:02 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-02-21 222504]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-18 104936]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-09-24 210216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2008-02-22 62760]
"UpdatePPShortCut"="c:\program files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-22 210216]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-04-29 981688]
"SSDMonitor"="c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2012-02-03 103896]
.
c:\users\diviak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-10-4 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-12-11 315496]
R3 cdrombus;Android BUS Service;c:\windows\system32\Drivers\cdrombus.sys [2012-08-22 19968]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-06-19 102912]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-06-18 51928]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 95408]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2015-04-29 284504]
R3 qcusbser;Android USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\qcusbser.sys [2013-01-16 205312]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-08 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 MpKsle6033213;MpKsle6033213;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\MpKsle6033213.sys [2015-08-07 39168]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2012-02-03 793048]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-06-18 23256]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
utcsvc REG_MULTI_SZ DiagTrack
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cd607a4c9a22cb.job
- c:\users\diviak\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-21 22:04]
.
2011-10-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000UA.job
- c:\users\diviak\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-21 22:04]
.
2015-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1ca30d04c6389b8.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2015-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf523bb685f195.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2014-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf6b9aa7cc50e2.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2015-02-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d02f4d4204f075.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d043071fb3c688.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2015-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d0bff068180956.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2011-10-25 c:\windows\Tasks\Norton Security Scan for diviak.job
- c:\progra~1\NORTON~2\Engine\351~1.8\Nss.exe [2011-10-23 13:59]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\program files\PartyGaming\PartyCasino\RunCasino.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\diviak\AppData\Roaming\Mozilla\Firefox\Profiles\y1d7q3h9.default\
.
- - - - ORPHANS REMOVED - - - -
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.11.149\SSScheduler.exe
AddRemove-McAfee Security Scan - c:\program files\McAfee Security Scan\uninstall.exe
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\GWX\GWX.exe
c:\windows\system32\sppsvc.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2015-08-08 12:01:24 - machine was rebooted
ComboFix-quarantined-files.txt 2015-08-08 10:01
ComboFix2.txt 2015-08-08 08:53
.
Pre-Run: 43 875 414 016 bytes free
Post-Run: 43 469 639 680 bytes free
.
- - End Of File - - B8F5C0912DF48218D97E7DC6E5629065
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.3037.1600 [GMT 2:00]
Running from: c:\users\diviak\Desktop\ComboFix.exe
Command switches used :: c:\users\diviak\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cd607a4c9a22cb.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1ca30d04c6389b8.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf523bb685f195.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf6b9aa7cc50e2.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d02f4d4204f075.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d043071fb3c688.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d0bff068180956.job"
"c:\windows\Tasks\Norton Security Scan for diviak.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\McAfee Security Scan
c:\program files\McAfee Security Scan\3.11.149\AVScanComponent.dll
c:\program files\McAfee Security Scan\3.11.149\AVScanner.ini
c:\program files\McAfee Security Scan\3.11.149\avvclean.dat
c:\program files\McAfee Security Scan\3.11.149\avvnames.dat
c:\program files\McAfee Security Scan\3.11.149\avvscan.dat
c:\program files\McAfee Security Scan\3.11.149\config.dat
c:\program files\McAfee Security Scan\3.11.149\ftconfig.ini
c:\program files\McAfee Security Scan\3.11.149\McAfee.ico
c:\program files\McAfee Security Scan\3.11.149\mcbrwsr2.dll
c:\program files\McAfee Security Scan\3.11.149\MCCompHostConfig.ini
c:\program files\McAfee Security Scan\3.11.149\McCHSvc.exe
c:\program files\McAfee Security Scan\3.11.149\McInstallerRes.dll
c:\program files\McAfee Security Scan\3.11.149\McInstallerRes_LD.dll
c:\program files\McAfee Security Scan\3.11.149\McInstallerStartup.dll
c:\program files\McAfee Security Scan\3.11.149\mcscan32.dll
c:\program files\McAfee Security Scan\3.11.149\McUICnt.exe
c:\program files\McAfee Security Scan\3.11.149\McUpdater.dll
c:\program files\McAfee Security Scan\3.11.149\sa_cache_sqlite.dll
c:\program files\McAfee Security Scan\3.11.149\sa_http_win32.dll
c:\program files\McAfee Security Scan\3.11.149\sa_mbl.dll
c:\program files\McAfee Security Scan\3.11.149\sa_store_sqlite.dll
c:\program files\McAfee Security Scan\3.11.149\sacore.db
c:\program files\McAfee Security Scan\3.11.149\sacore.dll
c:\program files\McAfee Security Scan\3.11.149\sacoredata\uds_filetypes.txt
c:\program files\McAfee Security Scan\3.11.149\sacoredata\uds_hosting.txt
c:\program files\McAfee Security Scan\3.11.149\sacoredata\uds_tlds.txt
c:\program files\McAfee Security Scan\3.11.149\SecurityScanner.dll
c:\program files\McAfee Security Scan\3.11.149\SecurityScanner_LD.dll
c:\program files\McAfee Security Scan\3.11.149\signlic.txt
c:\program files\McAfee Security Scan\3.11.149\sqlite3.dll
c:\program files\McAfee Security Scan\3.11.149\SSScheduler.exe
c:\program files\McAfee Security Scan\3.11.149\uninstaller.ini
c:\program files\McAfee Security Scan\3.11.149\WebInfoScanner.dll
c:\program files\McAfee Security Scan\3.11.149\WMIScanner.dll
c:\program files\McAfee Security Scan\uninstall.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_BBSvc
-------\Service_BBUpdate
-------\Service_McComponentHostService
.
.
((((((((((((((((((((((((( Files Created from 2015-07-08 to 2015-08-08 )))))))))))))))))))))))))))))))
.
.
2015-08-07 14:21 . 2015-08-07 14:21 -------- d-----w- c:\users\diviak\AppData\Roaming\HD Tune Pro
2015-08-07 14:21 . 2015-08-07 14:21 -------- d-----w- c:\program files\HD Tune Pro
2015-08-07 14:14 . 2015-08-07 14:14 -------- d-----w- c:\windows\system32\wbem\Framework
2015-08-07 14:14 . 2015-08-07 14:14 39168 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\MpKsle6033213.sys
2015-08-07 12:38 . 2015-08-07 12:38 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\offreg.804.dll
2015-08-07 09:08 . 2015-07-01 14:41 912000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A4043178-625C-43D8-822A-89BBCC57B46D}\gapaengine.dll
2015-08-07 09:05 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\mpengine.dll
2015-08-06 20:13 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-08-06 09:48 . 2015-08-07 12:39 98520 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-06 09:47 . 2015-08-06 09:47 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-08-06 09:47 . 2015-08-06 09:47 -------- d-----w- c:\programdata\Malwarebytes
2015-08-06 09:47 . 2015-06-18 06:41 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-08-06 09:47 . 2015-06-18 06:41 94936 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-08-06 09:47 . 2015-06-18 06:41 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-08-06 09:31 . 2015-08-07 08:55 -------- d-----w- C:\AdwCleaner
2015-08-05 08:52 . 2015-08-05 08:53 -------- d-----w- C:\rsit
2015-08-05 08:52 . 2015-08-05 08:52 -------- d-----w- c:\program files\trend micro
2015-07-29 05:23 . 2015-07-25 17:47 587264 ----a-w- c:\windows\system32\generaltel.dll
2015-07-29 05:23 . 2015-07-25 17:47 628736 ----a-w- c:\windows\system32\invagent.dll
2015-07-29 05:23 . 2015-07-25 17:46 342016 ----a-w- c:\windows\system32\devinv.dll
2015-07-29 05:23 . 2015-07-25 17:46 924160 ----a-w- c:\windows\system32\appraiser.dll
2015-07-29 05:23 . 2015-07-25 17:46 58880 ----a-w- c:\windows\system32\acmigration.dll
2015-07-29 05:23 . 2015-07-25 17:40 932864 ----a-w- c:\windows\system32\aeinv.dll
2015-07-29 05:23 . 2015-07-25 17:51 15808 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-07-29 05:23 . 2015-07-25 17:46 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-07-21 15:31 . 2015-07-15 02:55 26624 ----a-w- c:\windows\system32\lpk.dll
2015-07-21 15:31 . 2015-07-15 02:55 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-07-21 15:31 . 2015-07-15 02:55 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-07-21 15:31 . 2015-07-15 02:55 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-07-21 15:31 . 2015-07-15 01:52 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-07-16 18:37 . 2015-06-15 21:47 101824 ----a-w- c:\windows\system32\consent.exe
2015-07-16 18:37 . 2015-06-15 21:43 2364416 ----a-w- c:\windows\system32\msi.dll
2015-07-16 18:37 . 2015-06-15 21:43 1805824 ----a-w- c:\windows\system32\authui.dll
2015-07-16 18:37 . 2015-06-15 21:43 337408 ----a-w- c:\windows\system32\msihnd.dll
2015-07-16 18:37 . 2015-06-15 21:43 47104 ----a-w- c:\windows\system32\appinfo.dll
2015-07-16 18:37 . 2015-06-15 21:42 73216 ----a-w- c:\windows\system32\msiexec.exe
2015-07-16 18:37 . 2015-06-15 21:37 25088 ----a-w- c:\windows\system32\msimsg.dll
2015-07-15 20:57 . 2015-06-25 08:46 2383872 ----a-w- c:\windows\system32\win32k.sys
2015-07-15 20:55 . 2015-07-04 17:48 1414656 ----a-w- c:\windows\system32\ole32.dll
2015-07-15 20:55 . 2015-06-17 17:39 305664 ----a-w- c:\windows\system32\gdi32.dll
2015-07-15 20:55 . 2015-04-27 19:04 143872 ----a-w- c:\windows\system32\cryptsvc.dll
2015-07-15 20:55 . 2015-04-27 19:04 1174528 ----a-w- c:\windows\system32\crypt32.dll
2015-07-15 20:55 . 2015-04-27 19:05 179200 ----a-w- c:\windows\system32\wintrust.dll
2015-07-15 20:55 . 2015-04-27 19:04 103936 ----a-w- c:\windows\system32\cryptnet.dll
2015-07-15 20:44 . 2015-06-19 18:31 37888 ----a-w- c:\program files\Internet Explorer\DiagnosticsHub_is.dll
2015-07-15 20:43 . 2015-06-19 17:53 817664 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2015-07-15 20:43 . 2015-06-19 18:25 504320 ----a-w- c:\windows\system32\vbscript.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-05 10:11 . 2011-05-08 13:10 246952 ------w- c:\windows\system32\MpSigStub.exe
2015-07-01 20:30 . 2015-07-15 20:56 248832 ----a-w- c:\windows\system32\schannel.dll
2015-07-01 14:41 . 2011-05-26 06:04 912000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2015-06-16 23:01 . 2015-06-16 23:01 1202856 ----a-w- c:\windows\system32\FM20.DLL
2015-05-25 18:07 . 2015-06-10 07:07 3989440 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-05-25 18:07 . 2015-06-10 07:07 3934144 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-05-25 18:04 . 2015-06-10 07:07 1307648 ----a-w- c:\windows\system32\ntdll.dll
2015-05-25 18:01 . 2015-06-10 07:07 853504 ----a-w- c:\windows\system32\diagtrack.dll
2015-05-25 18:01 . 2015-06-10 07:06 635392 ----a-w- c:\windows\system32\tdh.dll
2015-05-25 18:01 . 2015-06-10 07:07 400896 ----a-w- c:\windows\system32\srcore.dll
2015-05-25 18:01 . 2015-06-10 07:06 43008 ----a-w- c:\windows\system32\srclient.dll
2015-05-25 18:01 . 2015-06-10 07:06 92160 ----a-w- c:\windows\system32\sechost.dll
2015-05-25 18:01 . 2015-06-10 07:06 38912 ----a-w- c:\windows\system32\csrsrv.dll
2015-05-25 18:01 . 2015-06-10 07:07 641536 ----a-w- c:\windows\system32\advapi32.dll
2015-05-25 18:00 . 2015-06-10 07:06 40448 ----a-w- c:\windows\system32\typeperf.exe
2015-05-25 18:00 . 2015-06-10 07:07 364544 ----a-w- c:\windows\system32\tracerpt.exe
2015-05-25 18:00 . 2015-06-10 07:06 69632 ----a-w- c:\windows\system32\smss.exe
2015-05-25 18:00 . 2015-06-10 07:07 262656 ----a-w- c:\windows\system32\rstrui.exe
2015-05-25 18:00 . 2015-06-10 07:06 37888 ----a-w- c:\windows\system32\relog.exe
2015-05-25 18:00 . 2015-06-10 07:07 82944 ----a-w- c:\windows\system32\logman.exe
2015-05-25 18:00 . 2015-06-10 07:06 17408 ----a-w- c:\windows\system32\diskperf.exe
2015-05-25 17:55 . 2015-06-10 07:06 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-05-25 16:53 . 2015-06-10 07:06 36864 ----a-w- c:\windows\system32\UtcResources.dll
2015-05-21 13:20 . 2015-06-10 07:08 163840 ----a-w- c:\windows\system32\aepic.dll
2006-06-15 18:33 . 2011-05-10 22:23 233472 ----a-w- c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-25 16:43 . 2011-05-10 22:23 204895 ----a-w- c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 12:41 . 2011-05-10 22:23 77824 ----a-w- c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2006-06-19 11:10 . 2011-05-10 22:23 426081 ----a-w- c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 10:19 . 2011-05-10 22:23 458752 ----a-w- c:\program files\mozilla firefox\plugins\imagickrt.dll
2006-04-10 16:35 . 2011-05-10 22:23 139264 ----a-w- c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 09:10 . 2011-05-10 22:23 204800 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 09:42 . 2011-05-10 22:23 106496 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 09:22 . 2011-05-10 22:23 212992 ----a-w- c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 09:21 . 2011-05-10 22:23 167936 ----a-w- c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
2011-03-18 18:05 . 2011-05-08 13:02 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-02-21 222504]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-18 104936]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-09-24 210216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2008-02-22 62760]
"UpdatePPShortCut"="c:\program files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-22 210216]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-04-29 981688]
"SSDMonitor"="c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2012-02-03 103896]
.
c:\users\diviak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-10-4 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-12-11 315496]
R3 cdrombus;Android BUS Service;c:\windows\system32\Drivers\cdrombus.sys [2012-08-22 19968]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-06-19 102912]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-06-18 51928]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 95408]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2015-04-29 284504]
R3 qcusbser;Android USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\qcusbser.sys [2013-01-16 205312]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-08 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 MpKsle6033213;MpKsle6033213;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BABA7280-8A5F-4B54-930B-536416FCAB9F}\MpKsle6033213.sys [2015-08-07 39168]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2012-02-03 793048]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-06-18 23256]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
utcsvc REG_MULTI_SZ DiagTrack
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cd607a4c9a22cb.job
- c:\users\diviak\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-21 22:04]
.
2011-10-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000UA.job
- c:\users\diviak\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-21 22:04]
.
2015-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1ca30d04c6389b8.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2015-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf523bb685f195.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2014-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1cf6b9aa7cc50e2.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2015-02-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d02f4d4204f075.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d043071fb3c688.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2015-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3296201877-1619235930-2648828280-1000Core1d0bff068180956.job
- c:\users\diviak\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 16:23]
.
2011-10-25 c:\windows\Tasks\Norton Security Scan for diviak.job
- c:\progra~1\NORTON~2\Engine\351~1.8\Nss.exe [2011-10-23 13:59]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\program files\PartyGaming\PartyCasino\RunCasino.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\diviak\AppData\Roaming\Mozilla\Firefox\Profiles\y1d7q3h9.default\
.
- - - - ORPHANS REMOVED - - - -
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.11.149\SSScheduler.exe
AddRemove-McAfee Security Scan - c:\program files\McAfee Security Scan\uninstall.exe
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\GWX\GWX.exe
c:\windows\system32\sppsvc.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2015-08-08 12:01:24 - machine was rebooted
ComboFix-quarantined-files.txt 2015-08-08 10:01
ComboFix2.txt 2015-08-08 08:53
.
Pre-Run: 43 875 414 016 bytes free
Post-Run: 43 469 639 680 bytes free
.
- - End Of File - - B8F5C0912DF48218D97E7DC6E5629065
A36C5E4F47E84449FF07ED3517B43A31