Re: vir na flešce
Napsal: 03 lis 2013 13:52
ComboFix 13-11-03.02 - Acer 03.11.2013 13:37:24.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3956.2670 [GMT 1:00]
Spuštěný z: c:\stah\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Acer\AppData\Roaming\update_tc\update.exe
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
c:\windows\SysWow64\tmp6375.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Windows Internet Name Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-03 do 2013-11-03 )))))))))))))))))))))))))))))))
.
.
2013-11-03 12:45 . 2013-08-19 22:46 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FD8F235-83B1-4F85-AB3B-9B73C5ACE21D}\mpengine.dll
2013-11-03 10:48 . 2013-11-03 10:49 -------- d-----w- C:\AdwCleaner
2013-11-03 10:38 . 2013-11-03 10:38 -------- d-----w- c:\windows\ERUNT
2013-11-03 10:36 . 2013-11-03 10:36 -------- d-----w- c:\users\Acer\AppData\Roaming\AVAST Software
2013-11-03 10:35 . 2013-11-03 10:35 65264 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-11-03 10:35 . 2013-11-03 10:35 205320 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-11-03 10:35 . 2013-11-03 10:35 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-11-03 10:35 . 2013-11-03 10:35 1032416 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-11-03 10:35 . 2013-11-03 10:35 409832 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-11-03 10:35 . 2013-11-03 10:35 84328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-11-03 10:35 . 2013-11-03 10:35 38984 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-11-03 10:35 . 2013-11-03 10:35 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-11-03 10:35 . 2013-11-03 10:35 43152 ----a-w- c:\windows\avastSS.scr
2013-11-03 10:35 . 2013-11-03 10:35 -------- d-----w- c:\program files\AVAST Software
2013-11-03 09:14 . 2013-11-03 09:14 -------- d-----w- C:\rsit
2013-11-03 09:14 . 2013-11-03 09:14 -------- d-----w- c:\program files\trend micro
2013-11-03 08:48 . 2013-11-03 08:54 -------- d-----w- C:\UsbFix
2013-11-02 17:05 . 2013-11-02 17:05 388096 ----a-r- c:\users\Acer\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-11-02 17:05 . 2013-11-02 17:05 -------- d-----w- c:\program files (x86)\Trend Micro
2013-11-02 16:37 . 2013-11-02 16:37 -------- d-----w- c:\users\Acer\AppData\Local\GHISLER
2013-11-01 19:46 . 2013-11-01 19:46 -------- d-----w- c:\windows\6833245EDD86479A882A8360D62C8194.TMP
2013-11-01 19:28 . 2013-11-01 19:28 -------- d-----w- c:\program files (x86)\Eidos
2013-10-20 10:39 . 2013-10-20 10:47 -------- d-----w- c:\program files (x86)\Vietcong2
2013-10-20 10:37 . 2013-10-20 10:37 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll
2013-10-19 12:21 . 2013-10-19 12:29 -------- d-----w- c:\program files (x86)\LCP
2013-10-19 12:21 . 2013-10-19 12:21 26624 ----a-r- c:\users\Acer\AppData\Roaming\Microsoft\Installer\{1EFAF492-9A3B-48C3-9349-234B146FDA46}\Icon1EFAF492.exe
2013-10-18 16:15 . 2013-11-02 15:51 -------- d-----w- c:\users\Acer\AppData\Local\download.am-data
2013-10-18 16:15 . 2013-10-18 16:15 -------- d-----w- c:\program files (x86)\Download.am
2013-10-18 13:58 . 2013-10-18 13:58 -------- d-----w- C:\Games
2013-10-12 15:43 . 2013-10-12 15:43 -------- d-----w- c:\program files (x86)\Cenega Czech
2013-10-12 11:41 . 2013-10-12 11:49 -------- d-----w- c:\users\Acer\AppData\Local\Floorball League
2013-10-12 11:41 . 2013-10-12 11:41 -------- d-----w- c:\program files (x86)\Prodigium Game Studios
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-03 10:35 . 2013-03-08 08:12 334648 ----a-w- c:\windows\system32\aswBoot.exe
2013-10-12 11:43 . 2013-05-12 14:20 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2013-10-12 11:43 . 2013-05-12 14:20 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2013-10-12 09:01 . 2013-08-08 15:42 4464 ----a-w- c:\windows\SysWow64\ealregsnapshot1.reg
2013-09-25 08:47 . 2013-07-25 17:46 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-09-25 08:47 . 2013-07-18 17:46 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-09-24 07:53 . 2013-07-18 17:46 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-09-24 07:52 . 2013-07-18 17:46 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-09-22 16:33 . 2013-09-22 16:33 82432 ----a-w- c:\windows\SysWow64\msxml4r.dll
2013-09-22 16:33 . 2013-09-22 16:33 1233920 ----a-w- c:\windows\SysWow64\msxml4.dll
2013-08-31 10:16 . 2013-08-31 10:16 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
2013-08-30 08:36 . 2013-08-30 08:36 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-30 08:36 . 2013-08-30 08:36 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-08-30 08:31 . 2013-08-30 08:31 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-08-30 08:31 . 2013-08-30 08:31 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-30 08:31 . 2013-08-30 08:31 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-08-30 08:31 . 2013-08-30 08:31 86016 ----a-w- c:\windows\system32\jsproxy.dll
2013-08-30 08:31 . 2013-08-30 08:31 816640 ----a-w- c:\windows\system32\jscript.dll
2013-08-30 08:31 . 2013-08-30 08:31 729088 ----a-w- c:\windows\system32\msfeeds.dll
2013-08-30 08:31 . 2013-08-30 08:31 599040 ----a-w- c:\windows\system32\vbscript.dll
2013-08-30 08:31 . 2013-08-30 08:31 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-08-30 08:31 . 2013-08-30 08:31 248320 ----a-w- c:\windows\system32\ieui.dll
2013-08-30 08:31 . 2013-08-30 08:31 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-08-30 08:31 . 2013-08-30 08:31 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-08-30 08:31 . 2013-08-30 08:31 237056 ----a-w- c:\windows\system32\url.dll
2013-08-30 08:31 . 2013-08-30 08:31 2312704 ----a-w- c:\windows\system32\jscript9.dll
2013-08-30 08:31 . 2013-08-30 08:31 2147840 ----a-w- c:\windows\system32\iertutil.dll
2013-08-30 08:31 . 2013-08-30 08:31 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-08-30 08:31 . 2013-08-30 08:31 17830400 ----a-w- c:\windows\system32\mshtml.dll
2013-08-30 08:31 . 2013-08-30 08:31 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-30 08:31 . 2013-08-30 08:31 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-30 08:31 . 2013-08-30 08:31 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-08-30 08:31 . 2013-08-30 08:31 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-08-30 08:31 . 2013-08-30 08:31 1392128 ----a-w- c:\windows\system32\wininet.dll
2013-08-30 08:31 . 2013-08-30 08:31 1346560 ----a-w- c:\windows\system32\urlmon.dll
2013-08-30 08:31 . 2013-08-30 08:31 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2013-08-30 08:31 . 2013-08-30 08:31 10926080 ----a-w- c:\windows\system32\ieframe.dll
2013-08-30 08:29 . 2013-08-30 08:29 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-08-30 08:29 . 2013-08-30 08:29 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-30 08:29 . 2013-08-30 08:29 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-08-30 08:29 . 2013-08-30 08:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-08-30 08:29 . 2013-08-30 08:29 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-08-30 08:29 . 2013-08-30 08:29 3913664 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-08-30 08:29 . 2013-08-30 08:29 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-08-30 08:29 . 2013-08-30 08:29 243712 ----a-w- c:\windows\system32\wow64.dll
2013-08-30 08:29 . 2013-08-30 08:29 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-08-30 08:29 . 2013-08-30 08:29 1732032 ----a-w- c:\windows\system32\ntdll.dll
2013-08-30 08:29 . 2013-08-30 08:29 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-08-30 08:29 . 2013-08-30 08:29 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2013-08-30 08:29 . 2013-08-30 08:29 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-08-30 08:29 . 2013-08-30 08:29 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-30 08:29 . 2013-08-30 08:29 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-30 08:29 . 2013-08-30 08:29 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-30 08:28 . 2013-08-30 08:28 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-08-30 08:28 . 2013-08-30 08:28 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-30 08:28 . 2013-08-30 08:28 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-08-30 08:28 . 2013-08-30 08:28 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-08-30 08:28 . 2013-08-30 08:28 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-08-30 08:28 . 2013-08-30 08:28 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-30 08:28 . 2013-08-30 08:28 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-08-30 08:28 . 2013-08-30 08:28 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-08-19 22:46 . 2013-08-30 08:36 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AAEB1A84-B8AC-4F73-8BE4-A2469DCCC832}\mpengine.dll
2013-08-07 02:22 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-11-03 3568312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys;c:\windows\SYSNATIVE\drivers\aswFsBlk.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-8095715-4125419755-1740114249-1000Core.job
- c:\users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-05-22 16:09]
.
2013-11-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-8095715-4125419755-1740114249-1000UA.job
- c:\users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-05-22 16:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-11-03 10:35 326944 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-10 9643552]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-22 323584]
"rqcqyuxmeb"="wscript.exe" [2009-07-14 168960]
"pstfsvapsu"="wscript.exe" [2009-07-14 168960]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
mDefault_Page_URL = hxxp://www.google.com
TCP: DhcpNameServer = 10.132.12.33 10.132.12.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-Printsrv - c:\windows\System32\Printing_Admin_Scripts\en-US\pubpr.vbs
AddRemove-MixiDJ chrome Toolbar - c:\users\Acer\AppData\Roaming\BabSolution\Shared\GUninstaller.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-8095715-4125419755-1740114249-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:f8,18,33,6b,da,3f,88,bf,3e,d0,d5,0d,00,b0,2b,e3,31,40,d3,25,80,32,22,
07,d3,4b,0b,49,f3,54,2a,0b,c3,f4,8d,7d,95,73,68,3a,1e,16,64,9c,96,dc,9a,90,\
"??"=hex:13,84,26,0d,e6,e0,d3,09,2c,a0,1a,d8,08,6a,dd,6c
.
[HKEY_USERS\S-1-5-21-8095715-4125419755-1740114249-1000\Software\SecuROM\License information*]
"datasecu"=hex:dd,99,61,1e,d6,75,99,bb,d4,3c,e3,4d,95,f4,1e,1d,3e,95,87,b9,c1,
98,08,60,bc,e1,04,cb,a7,a0,d9,83,16,75,88,67,46,3e,83,cf,ed,94,cc,cd,8b,e5,\
"rkeysecu"=hex:92,3d,d7,e7,0d,c8,84,39,50,97,8d,fa,b4,af,b4,78
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2013-11-03 13:50:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-03 12:50
.
Před spuštěním: Volných bajtů: 76 976 504 832
Po spuštění: Volných bajtů: 76 755 107 840
.
- - End Of File - - C00B344E62A5E1323A3EC75EDF74C10E
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3956.2670 [GMT 1:00]
Spuštěný z: c:\stah\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Acer\AppData\Roaming\update_tc\update.exe
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
c:\windows\SysWow64\tmp6375.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Windows Internet Name Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-03 do 2013-11-03 )))))))))))))))))))))))))))))))
.
.
2013-11-03 12:45 . 2013-08-19 22:46 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FD8F235-83B1-4F85-AB3B-9B73C5ACE21D}\mpengine.dll
2013-11-03 10:48 . 2013-11-03 10:49 -------- d-----w- C:\AdwCleaner
2013-11-03 10:38 . 2013-11-03 10:38 -------- d-----w- c:\windows\ERUNT
2013-11-03 10:36 . 2013-11-03 10:36 -------- d-----w- c:\users\Acer\AppData\Roaming\AVAST Software
2013-11-03 10:35 . 2013-11-03 10:35 65264 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-11-03 10:35 . 2013-11-03 10:35 205320 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-11-03 10:35 . 2013-11-03 10:35 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-11-03 10:35 . 2013-11-03 10:35 1032416 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-11-03 10:35 . 2013-11-03 10:35 409832 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-11-03 10:35 . 2013-11-03 10:35 84328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-11-03 10:35 . 2013-11-03 10:35 38984 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-11-03 10:35 . 2013-11-03 10:35 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-11-03 10:35 . 2013-11-03 10:35 43152 ----a-w- c:\windows\avastSS.scr
2013-11-03 10:35 . 2013-11-03 10:35 -------- d-----w- c:\program files\AVAST Software
2013-11-03 09:14 . 2013-11-03 09:14 -------- d-----w- C:\rsit
2013-11-03 09:14 . 2013-11-03 09:14 -------- d-----w- c:\program files\trend micro
2013-11-03 08:48 . 2013-11-03 08:54 -------- d-----w- C:\UsbFix
2013-11-02 17:05 . 2013-11-02 17:05 388096 ----a-r- c:\users\Acer\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-11-02 17:05 . 2013-11-02 17:05 -------- d-----w- c:\program files (x86)\Trend Micro
2013-11-02 16:37 . 2013-11-02 16:37 -------- d-----w- c:\users\Acer\AppData\Local\GHISLER
2013-11-01 19:46 . 2013-11-01 19:46 -------- d-----w- c:\windows\6833245EDD86479A882A8360D62C8194.TMP
2013-11-01 19:28 . 2013-11-01 19:28 -------- d-----w- c:\program files (x86)\Eidos
2013-10-20 10:39 . 2013-10-20 10:47 -------- d-----w- c:\program files (x86)\Vietcong2
2013-10-20 10:37 . 2013-10-20 10:37 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll
2013-10-19 12:21 . 2013-10-19 12:29 -------- d-----w- c:\program files (x86)\LCP
2013-10-19 12:21 . 2013-10-19 12:21 26624 ----a-r- c:\users\Acer\AppData\Roaming\Microsoft\Installer\{1EFAF492-9A3B-48C3-9349-234B146FDA46}\Icon1EFAF492.exe
2013-10-18 16:15 . 2013-11-02 15:51 -------- d-----w- c:\users\Acer\AppData\Local\download.am-data
2013-10-18 16:15 . 2013-10-18 16:15 -------- d-----w- c:\program files (x86)\Download.am
2013-10-18 13:58 . 2013-10-18 13:58 -------- d-----w- C:\Games
2013-10-12 15:43 . 2013-10-12 15:43 -------- d-----w- c:\program files (x86)\Cenega Czech
2013-10-12 11:41 . 2013-10-12 11:49 -------- d-----w- c:\users\Acer\AppData\Local\Floorball League
2013-10-12 11:41 . 2013-10-12 11:41 -------- d-----w- c:\program files (x86)\Prodigium Game Studios
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-03 10:35 . 2013-03-08 08:12 334648 ----a-w- c:\windows\system32\aswBoot.exe
2013-10-12 11:43 . 2013-05-12 14:20 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2013-10-12 11:43 . 2013-05-12 14:20 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2013-10-12 09:01 . 2013-08-08 15:42 4464 ----a-w- c:\windows\SysWow64\ealregsnapshot1.reg
2013-09-25 08:47 . 2013-07-25 17:46 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-09-25 08:47 . 2013-07-18 17:46 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-09-24 07:53 . 2013-07-18 17:46 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-09-24 07:52 . 2013-07-18 17:46 282296 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-09-22 16:33 . 2013-09-22 16:33 82432 ----a-w- c:\windows\SysWow64\msxml4r.dll
2013-09-22 16:33 . 2013-09-22 16:33 1233920 ----a-w- c:\windows\SysWow64\msxml4.dll
2013-08-31 10:16 . 2013-08-31 10:16 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
2013-08-30 08:36 . 2013-08-30 08:36 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-30 08:36 . 2013-08-30 08:36 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-08-30 08:31 . 2013-08-30 08:31 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-08-30 08:31 . 2013-08-30 08:31 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-30 08:31 . 2013-08-30 08:31 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-08-30 08:31 . 2013-08-30 08:31 86016 ----a-w- c:\windows\system32\jsproxy.dll
2013-08-30 08:31 . 2013-08-30 08:31 816640 ----a-w- c:\windows\system32\jscript.dll
2013-08-30 08:31 . 2013-08-30 08:31 729088 ----a-w- c:\windows\system32\msfeeds.dll
2013-08-30 08:31 . 2013-08-30 08:31 599040 ----a-w- c:\windows\system32\vbscript.dll
2013-08-30 08:31 . 2013-08-30 08:31 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-08-30 08:31 . 2013-08-30 08:31 248320 ----a-w- c:\windows\system32\ieui.dll
2013-08-30 08:31 . 2013-08-30 08:31 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-08-30 08:31 . 2013-08-30 08:31 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-08-30 08:31 . 2013-08-30 08:31 237056 ----a-w- c:\windows\system32\url.dll
2013-08-30 08:31 . 2013-08-30 08:31 2312704 ----a-w- c:\windows\system32\jscript9.dll
2013-08-30 08:31 . 2013-08-30 08:31 2147840 ----a-w- c:\windows\system32\iertutil.dll
2013-08-30 08:31 . 2013-08-30 08:31 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-08-30 08:31 . 2013-08-30 08:31 17830400 ----a-w- c:\windows\system32\mshtml.dll
2013-08-30 08:31 . 2013-08-30 08:31 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-30 08:31 . 2013-08-30 08:31 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-30 08:31 . 2013-08-30 08:31 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-08-30 08:31 . 2013-08-30 08:31 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-08-30 08:31 . 2013-08-30 08:31 1392128 ----a-w- c:\windows\system32\wininet.dll
2013-08-30 08:31 . 2013-08-30 08:31 1346560 ----a-w- c:\windows\system32\urlmon.dll
2013-08-30 08:31 . 2013-08-30 08:31 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2013-08-30 08:31 . 2013-08-30 08:31 10926080 ----a-w- c:\windows\system32\ieframe.dll
2013-08-30 08:29 . 2013-08-30 08:29 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-08-30 08:29 . 2013-08-30 08:29 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-30 08:29 . 2013-08-30 08:29 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-08-30 08:29 . 2013-08-30 08:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-08-30 08:29 . 2013-08-30 08:29 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-08-30 08:29 . 2013-08-30 08:29 3913664 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-08-30 08:29 . 2013-08-30 08:29 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-08-30 08:29 . 2013-08-30 08:29 243712 ----a-w- c:\windows\system32\wow64.dll
2013-08-30 08:29 . 2013-08-30 08:29 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-08-30 08:29 . 2013-08-30 08:29 1732032 ----a-w- c:\windows\system32\ntdll.dll
2013-08-30 08:29 . 2013-08-30 08:29 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-08-30 08:29 . 2013-08-30 08:29 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2013-08-30 08:29 . 2013-08-30 08:29 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-08-30 08:29 . 2013-08-30 08:29 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-30 08:29 . 2013-08-30 08:29 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-30 08:29 . 2013-08-30 08:29 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-30 08:28 . 2013-08-30 08:28 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-08-30 08:28 . 2013-08-30 08:28 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-30 08:28 . 2013-08-30 08:28 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-08-30 08:28 . 2013-08-30 08:28 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-08-30 08:28 . 2013-08-30 08:28 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-08-30 08:28 . 2013-08-30 08:28 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-30 08:28 . 2013-08-30 08:28 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-08-30 08:28 . 2013-08-30 08:28 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-08-19 22:46 . 2013-08-30 08:36 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AAEB1A84-B8AC-4F73-8BE4-A2469DCCC832}\mpengine.dll
2013-08-07 02:22 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-11-03 3568312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys;c:\windows\SYSNATIVE\drivers\aswFsBlk.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-8095715-4125419755-1740114249-1000Core.job
- c:\users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-05-22 16:09]
.
2013-11-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-8095715-4125419755-1740114249-1000UA.job
- c:\users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-05-22 16:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-11-03 10:35 326944 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-10 9643552]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-22 323584]
"rqcqyuxmeb"="wscript.exe" [2009-07-14 168960]
"pstfsvapsu"="wscript.exe" [2009-07-14 168960]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
mDefault_Page_URL = hxxp://www.google.com
TCP: DhcpNameServer = 10.132.12.33 10.132.12.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-Printsrv - c:\windows\System32\Printing_Admin_Scripts\en-US\pubpr.vbs
AddRemove-MixiDJ chrome Toolbar - c:\users\Acer\AppData\Roaming\BabSolution\Shared\GUninstaller.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-8095715-4125419755-1740114249-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:f8,18,33,6b,da,3f,88,bf,3e,d0,d5,0d,00,b0,2b,e3,31,40,d3,25,80,32,22,
07,d3,4b,0b,49,f3,54,2a,0b,c3,f4,8d,7d,95,73,68,3a,1e,16,64,9c,96,dc,9a,90,\
"??"=hex:13,84,26,0d,e6,e0,d3,09,2c,a0,1a,d8,08,6a,dd,6c
.
[HKEY_USERS\S-1-5-21-8095715-4125419755-1740114249-1000\Software\SecuROM\License information*]
"datasecu"=hex:dd,99,61,1e,d6,75,99,bb,d4,3c,e3,4d,95,f4,1e,1d,3e,95,87,b9,c1,
98,08,60,bc,e1,04,cb,a7,a0,d9,83,16,75,88,67,46,3e,83,cf,ed,94,cc,cd,8b,e5,\
"rkeysecu"=hex:92,3d,d7,e7,0d,c8,84,39,50,97,8d,fa,b4,af,b4,78
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2013-11-03 13:50:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-03 12:50
.
Před spuštěním: Volných bajtů: 76 976 504 832
Po spuštění: Volných bajtů: 76 755 107 840
.
- - End Of File - - C00B344E62A5E1323A3EC75EDF74C10E
A36C5E4F47E84449FF07ED3517B43A31