ComboFix 12-11-22.03 - Nasgharet 22.11.2012 17:07:32.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1033.18.4095.2475 [GMT -8:00]
Spuštěný z: c:\users\Nasgharet\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-23 do 2012-11-23 )))))))))))))))))))))))))))))))
.
.
2012-12-21 01:02 . 2012-12-21 01:02 -------- d-----w- c:\users\Nasgharet\AppData\Local\OGUpdater
2012-12-21 00:54 . 2009-04-06 18:08 5174 ----a-w- c:\windows\SysWow64\nppt9x.vxd
2012-12-21 00:54 . 2009-04-06 18:08 4682 ----a-w- c:\windows\SysWow64\npptNT2.sys
2012-12-21 00:41 . 2012-12-21 00:41 -------- d-----w- c:\users\Nasgharet\AppData\Roaming\InstallShield
2012-11-23 01:16 . 2012-11-23 01:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-22 15:30 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-11-22 15:30 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-11-22 15:30 . 2012-10-15 15:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-11-22 15:30 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-11-22 15:30 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-11-22 15:30 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-11-22 15:30 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-11-22 15:28 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-11-22 15:28 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-11-22 15:28 . 2012-11-22 15:28 -------- d-----w- c:\programdata\AVAST Software
2012-11-22 15:28 . 2012-11-22 15:28 -------- d-----w- c:\program files\AVAST Software
2012-11-21 13:03 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE1F4FE3-DB91-4C26-8C8E-327BD20A540E}\mpengine.dll
2012-11-21 00:13 . 2012-11-21 00:13 -------- d-----w- C:\_OTL
2012-11-20 12:30 . 2012-11-20 12:30 -------- d-----w- c:\windows\SysWow64\Wat
2012-11-20 12:30 . 2012-11-20 12:30 -------- d-----w- c:\windows\system32\Wat
2012-11-20 11:38 . 2012-11-20 11:38 -------- d-----w- c:\program files (x86)\MSXML 4.0
2012-11-20 11:31 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-11-20 11:26 . 2012-11-20 11:26 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-11-20 11:03 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-11-20 11:03 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
2012-11-20 11:03 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
2012-11-20 11:03 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-11-20 11:03 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-11-19 21:53 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
2012-11-19 21:53 . 2010-08-21 05:36 738816 ----a-w- c:\windows\SysWow64\wmpmde.dll
2012-11-19 21:53 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll
2012-11-19 21:53 . 2012-08-24 17:10 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-11-19 21:53 . 2012-09-14 19:23 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-19 21:53 . 2012-09-14 18:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-11-19 18:10 . 2012-11-20 17:13 512 ----a-w- C:\PhysicalMBR.bin
2012-11-19 11:20 . 2011-10-26 05:22 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-11-19 11:19 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-11-19 11:18 . 2012-09-25 22:39 95744 ----a-w- c:\windows\system32\synceng.dll
2012-11-19 11:17 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
2012-11-19 02:05 . 2012-11-19 02:05 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-11-19 02:05 . 2012-09-30 03:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-19 02:03 . 2012-02-15 06:27 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-11-19 02:03 . 2012-02-15 05:44 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-11-19 02:03 . 2012-02-15 04:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-11-19 01:59 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-11-19 01:59 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-11-19 01:59 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-11-19 01:59 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-11-19 01:59 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-11-19 01:59 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-11-19 01:59 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-11-19 01:58 . 2012-06-02 23:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-11-19 01:58 . 2012-06-02 23:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-11-17 09:18 . 2012-11-17 09:18 -------- d-----w- c:\program files (x86)\trend micro
2012-11-16 22:59 . 2012-11-16 22:59 -------- d-----w- c:\users\Nasgharet\AppData\Local\Ahead
2012-11-16 22:59 . 2012-11-16 22:59 -------- d-----w- c:\users\Nasgharet\AppData\Local\Nero
2012-11-16 22:59 . 2012-11-16 22:59 -------- d-----w- c:\users\Nasgharet\AppData\Roaming\Nero
2012-11-16 22:50 . 2012-11-16 22:50 -------- d-----w- c:\program files (x86)\Common Files\Nero
2012-11-16 22:50 . 2012-11-16 22:50 -------- d-----w- c:\programdata\Nero
2012-11-16 22:50 . 2012-11-16 22:50 -------- d-----w- c:\program files (x86)\Nero
2012-11-16 22:42 . 2009-03-19 00:35 33856 ---ha-w- c:\windows\system32\hamachi.sys
2012-11-16 22:42 . 2012-11-16 22:42 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-11-16 16:12 . 2012-11-16 16:12 -------- d-----w- c:\users\Nasgharet\AppData\Local\Aeria Games
2012-11-16 16:11 . 2012-11-16 16:11 -------- d-----w- c:\programdata\Aeria Games
2012-11-16 16:08 . 2012-11-17 07:43 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
2012-11-16 16:08 . 2012-11-16 16:08 -------- d-----w- c:\program files (x86)\Aeria Games
2012-11-16 09:11 . 2012-11-17 07:43 -------- d-----w- C:\AeriaGames
2012-11-07 18:02 . 2012-11-07 18:02 -------- d-----w- c:\users\Nasgharet\AppData\Local\PokerStars.BE
2012-11-07 18:02 . 2012-11-07 18:02 -------- d-----w- c:\program files (x86)\PokerStars.BE
2012-11-07 17:48 . 2012-11-07 17:59 -------- d-----w- c:\users\Nasgharet\AppData\Local\FullTiltPoker
2012-11-07 17:48 . 2012-11-19 17:56 -------- d-----w- c:\program files (x86)\Full Tilt Poker
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-13 16:27 . 2012-09-05 20:19 15823872 ----a-w- c:\users\Nasgharet\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
2012-10-13 16:27 . 2012-09-05 20:19 786492 ----a-w- c:\users\Nasgharet\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe
2012-10-13 16:27 . 2012-09-05 20:19 107008 ----a-w- c:\users\Nasgharet\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
2012-09-05 20:35 . 2012-09-05 20:36 123231216 ----a-w- C:\World-of-Warcraft-Setup-enUS.exe
2012-09-05 19:37 . 2012-09-05 19:37 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-09-05 19:33 . 2012-09-05 19:33 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-05 19:33 . 2012-09-05 19:33 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-05 19:31 . 2012-09-05 19:31 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-05 19:31 . 2012-09-05 19:32 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-09-05 19:31 . 2012-09-05 19:32 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-10-19 1353080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-11-16 2254768]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R1 aswSnx;aswSnx; [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [x]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-20 1255736]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-05 283200]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-07-28 239616]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-16 2461104]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-30 676936]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-30 25928]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ASWFSBLK
*NewlyCreated* - ASWMONFLT
*NewlyCreated* - ASWRDR
*NewlyCreated* - ASWSP
*NewlyCreated* - ASWTDI
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
IE: {{878AC5FC-BE78-4bae-896C-7F75B790A71E} - c:\program files (x86)\PokerStars.BE\PokerStarsUpdate.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Nasgharet\AppData\Roaming\Mozilla\Firefox\Profiles\1kc8j041.default-1348185830213\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.com/
FF - ExtSQL: 2012-11-22 07:33;
wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Akamai - c:\users\Nasgharet\AppData\Local\Akamai\uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-11-22 17:20:54
ComboFix-quarantined-files.txt 2012-11-23 01:20
.
Před spuštěním: 32 582 811 648 bytes free
Po spuštění: 33 780 125 696 bytes free
.
- - End Of File - - 67A9A6D49AA3A1B33FAEA07056587853