Program jsem spustil, souhlasil jsem s licenčními podmínkami, program udělal kontrolu za cca 40 vteřin a pak se vypl.. Žádný log, žádný restart...
EDIT: Beru zpět.. byla to asi jen instalace.. zde je log
ComboFix 13-12-31.01 - Uzivatel 31.12.2013 13:12:50.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.8191.6023 [GMT 1:00]
Spuštěný z: c:\users\Uzivatel\Downloads\ComboFix.exe
AV: avast! Internet Security *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Internet Security *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Internet Security *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-28 do 2013-12-31 )))))))))))))))))))))))))))))))
.
.
2013-12-31 12:22 . 2013-12-31 12:22 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2013-12-31 12:22 . 2013-12-31 12:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-31 12:06 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0F0B379-0B69-4902-A504-528F5805083E}\mpengine.dll
2013-12-27 16:07 . 2013-12-27 16:26 -------- d-----w- c:\users\Uzivatel\AppData\Local\Torch
2013-12-27 16:05 . 2013-12-27 16:05 -------- d-----w- c:\users\Uzivatel\AppData\Local\ilividmoviestoolbarha
2013-12-23 18:56 . 2013-12-23 18:56 -------- d-----w- c:\program files (x86)\VS Revo Group
2013-12-21 16:59 . 2013-12-21 16:59 -------- d-----w- c:\programdata\Oracle
2013-12-21 16:59 . 2013-12-21 16:59 312744 ----a-w- c:\windows\system32\javaws.exe
2013-12-21 16:59 . 2013-12-21 16:59 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-12-21 16:59 . 2013-12-21 16:59 189352 ----a-w- c:\windows\system32\javaw.exe
2013-12-21 16:59 . 2013-12-21 16:59 189352 ----a-w- c:\windows\system32\java.exe
2013-12-15 20:44 . 2013-12-15 20:46 -------- d-----w- C:\AdwCleaner
2013-12-15 16:27 . 2013-12-30 18:59 -------- d-----w- C:\FRST
2013-12-12 19:47 . 2013-12-12 19:47 -------- d-----w- c:\users\Uzivatel\AppData\Local\Blizzard
2013-12-12 06:59 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-12 06:59 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-12 06:59 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 06:59 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 06:56 . 2013-12-12 06:56 -------- d-----w- c:\users\nikola
2013-12-09 19:15 . 2013-12-25 21:12 -------- d-----w- c:\program files (x86)\Hearthstone
2013-12-09 19:12 . 2013-12-09 19:12 -------- d-----w- c:\users\Uzivatel\AppData\Local\Blizzard Entertainment
2013-12-09 19:12 . 2013-12-30 21:02 -------- d-----w- c:\users\Uzivatel\AppData\Local\Battle.net
2013-12-09 19:12 . 2013-12-09 19:14 -------- d-----w- c:\users\Uzivatel\AppData\Roaming\Battle.net
2013-12-09 19:12 . 2013-12-25 20:53 -------- d-----w- c:\program files (x86)\Battle.net
2013-12-08 18:28 . 2013-12-25 11:59 -------- d-----w- c:\program files (x86)\osu!
2013-12-05 05:13 . 2013-12-05 05:13 -------- d-----w- c:\users\Uzivatel\AppData\Roaming\AVAST Software
2013-12-04 20:12 . 2013-12-04 20:12 -------- d-----w- c:\programdata\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-30 21:43 . 2010-10-06 15:13 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-12-30 21:43 . 2010-10-06 14:41 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-12-30 21:43 . 2010-10-06 14:41 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-12-16 15:00 . 2010-09-30 20:24 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-11 15:10 . 2012-06-30 08:17 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-11 15:10 . 2011-05-19 19:26 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-04 20:15 . 2013-04-18 11:38 205320 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-04 20:15 . 2013-04-18 11:38 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-12-04 20:15 . 2012-04-11 13:55 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-12-04 20:15 . 2012-04-11 13:55 1032416 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-04 20:15 . 2012-03-12 06:29 38984 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-12-04 20:15 . 2012-03-12 06:29 409832 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-04 20:15 . 2012-03-12 06:28 65264 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-04 20:15 . 2012-03-12 06:28 84328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-04 20:15 . 2012-03-12 06:28 43152 ----a-w- c:\windows\avastSS.scr
2013-12-04 20:15 . 2011-01-22 11:01 334648 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-04 20:15 . 2012-06-02 09:27 28184 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2013-12-04 20:15 . 2013-04-18 11:38 447888 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2013-12-01 13:10 . 2013-12-23 20:33 218200 ----a-w- c:\windows\SysWow64\unrar.dll
2013-11-26 06:33 . 2013-12-12 06:57 1820160 ----a-w- c:\windows\SysWow64\wininet.dll
2013-11-23 18:26 . 2013-12-11 15:10 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-19 15:06 . 2013-11-19 15:06 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-19 15:06 . 2013-11-19 15:06 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-19 15:06 . 2013-11-19 15:06 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-19 15:06 . 2013-11-19 15:06 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-19 15:06 . 2013-11-19 15:06 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-19 15:06 . 2013-11-19 15:06 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-19 15:06 . 2013-11-19 15:06 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-19 15:06 . 2013-11-19 15:06 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-19 15:06 . 2013-11-19 15:06 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-19 15:06 . 2013-11-19 15:06 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-19 15:06 . 2013-11-19 15:06 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-19 15:06 . 2013-11-19 15:06 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-19 15:06 . 2013-11-19 15:06 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-19 15:06 . 2013-11-19 15:06 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-19 15:06 . 2013-11-19 15:06 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-19 15:06 . 2013-11-19 15:06 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-19 15:06 . 2013-11-19 15:06 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-19 15:06 . 2013-11-19 15:06 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-19 15:06 . 2013-11-19 15:06 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-19 15:06 . 2013-11-19 15:06 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-19 15:06 . 2013-11-19 15:06 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-19 15:06 . 2013-11-19 15:06 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-19 15:06 . 2013-11-19 15:06 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-19 15:06 . 2013-11-19 15:06 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-19 15:06 . 2013-11-19 15:06 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-19 15:06 . 2013-11-19 15:06 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-19 15:06 . 2013-11-19 15:06 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-19 15:06 . 2013-11-19 15:06 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-19 15:06 . 2013-11-19 15:06 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-19 15:06 . 2013-11-19 15:06 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-19 15:06 . 2013-11-19 15:06 413696 ----a-w- c:\windows\system32\html.iec
2013-11-19 15:06 . 2013-11-19 15:06 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-19 15:06 . 2013-11-19 15:06 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-19 15:06 . 2013-11-19 15:06 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-19 15:06 . 2013-11-19 15:06 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-19 15:06 . 2013-11-19 15:06 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-19 15:06 . 2013-11-19 15:06 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-19 15:06 . 2013-11-19 15:06 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-19 15:06 . 2013-11-19 15:06 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-19 15:06 . 2013-11-19 15:06 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-19 15:06 . 2013-11-19 15:06 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-19 15:06 . 2013-11-19 15:06 235520 ----a-w- c:\windows\system32\url.dll
2013-11-19 15:06 . 2013-11-19 15:06 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-19 15:06 . 2013-11-19 15:06 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-19 15:06 . 2013-11-19 15:06 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-19 15:06 . 2013-11-19 15:06 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-19 15:06 . 2013-11-19 15:06 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-19 15:06 . 2013-11-19 15:06 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-19 15:06 . 2013-11-19 15:06 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-19 15:06 . 2013-11-19 15:06 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-19 15:06 . 2013-11-19 15:06 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-19 15:06 . 2013-11-19 15:06 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-19 15:06 . 2013-11-19 15:06 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-19 15:06 . 2013-11-19 15:06 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-19 15:06 . 2013-11-19 15:06 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-19 15:06 . 2013-11-19 15:06 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-19 15:06 . 2013-11-19 15:06 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-19 15:06 . 2013-11-19 15:06 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-19 15:06 . 2013-11-19 15:06 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-19 02:33 . 2010-09-30 20:29 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-12 02:07 . 2013-12-11 15:10 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-10-31 06:46 . 2012-06-02 09:27 270824 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2013-10-31 06:46 . 2012-06-02 09:27 131232 ----a-w- c:\windows\system32\drivers\aswFW.sys
2013-10-14 17:00 . 2013-11-19 15:11 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-10-12 02:30 . 2013-11-14 01:27 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-14 01:27 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-14 01:27 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:04 . 2013-12-11 15:10 121856 ----a-w- c:\windows\SysWow64\wshom.ocx
2013-10-12 02:03 . 2013-12-11 15:10 163840 ----a-w- c:\windows\SysWow64\scrrun.dll
2013-10-12 02:03 . 2013-11-14 01:27 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-14 01:27 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-12 01:15 . 2013-12-11 15:10 141824 ----a-w- c:\windows\SysWow64\wscript.exe
2013-10-05 20:25 . 2013-11-14 01:27 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-14 01:27 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-10-05 11:56 . 2010-10-06 14:41 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-10-04 02:28 . 2013-11-14 01:27 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-14 01:27 197120 ----a-w- c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-14 01:27 1930752 ----a-w- c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-14 01:27 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2013-06-01 802136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"DelReg"="c:\program files (x86)\MSI\OverclockingCenter\DelReg.exe" [2008-12-04 196608]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-08-11 2472048]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2013-12-04 3568312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
R2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys;c:\windows\SYSNATIVE\Drivers\btnetBus.sys [x]
R3 cpudrv64;cpudrv64;c:\program files (x86)\SystemRequirementsLab\cpudrv64.sys;c:\program files (x86)\SystemRequirementsLab\cpudrv64.sys [x]
R3 EagleX64;EagleX64; [x]
R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\1.3\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\1.3\temp\FairplayKD.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys;c:\windows\SYSNATIVE\Drivers\IvtBtBus.sys [x]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
R3 NTIOLib_1_0_6;NTIOLib_1_0_6;c:\program files (x86)\Setup Files\Ms7592vQB0\NTIOLib_X64.sys;c:\program files (x86)\Setup Files\Ms7592vQB0\NTIOLib_X64.sys [x]
R3 PCAlertDriver;PCAlertDriver;c:\program files (x86)\MSI\PC Alert 4\NTGLM7X64.sys;c:\program files (x86)\MSI\PC Alert 4\NTGLM7X64.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster\Driver\WinRing0x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys;c:\windows\SYSNATIVE\Drivers\BtHidBus.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdisFlt.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys;c:\windows\SYSNATIVE\drivers\aswFsBlk.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe;c:\program files\Alwil Software\Avast5\afwServ.exe [x]
S2 PSI_SVC_2_x64;Protexis Licensing V2 x64;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys;c:\windows\SYSNATIVE\DRIVERS\vcsvad.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-06 16:41 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-30 15:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-04 20:15 326944 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.search.ask.com/?o=APN10645A&gct=hp& ... 81-209&t=4
mLocal Page = c:\windows\SYSTEM32\blank.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{3d86a75b-cb6b-4764-885d-ca6336f04ba2} - c:\progra~2\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll
Toolbar-{3d86a75b-cb6b-4764-885d-ca6336f04ba2} - c:\progra~2\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll
Toolbar-10 - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-10 - (no file)
AddRemove-ilividmoviestoolbarhaCR - c:\progra~2\MOVIES~1\Datamngr\SRTOOL~1\GC\uninstall.exe
AddRemove-ilividmoviestoolbarhaIE - c:\progra~2\MOVIES~1\Datamngr\SRTOOL~1\IE\uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3279554059-404718991-3174698938-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*jpg*ţ˙˙˙¨Żw¨Żw\`ż·Ŕ ]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3279554059-404718991-3174698938-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*jpg*ţ˙˙˙¨Żw¨Żw\`ż·Ŕ \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3279554059-404718991-3174698938-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EC32C122-128B-A40D-1BD7-5D472B9824FB}*]
"haikbabkdpmcnich"=hex:6a,61,63,68,6c,6f,6c,6c,69,6a,62,62,6d,6a,64,62,62,6a,
68,6d,00,00
"iacjhejjkmigklpgbe"=hex:63,61,62,68,6b,6f,00,00
"iaghphdkpobdpbpjal"=hex:6a,61,63,68,6c,6f,6c,6c,69,6a,62,62,6d,6a,64,62,62,6a,
68,6d,00,00
"dbdhcgcblljpfglfdephlmoophmikghbcidkdhfd"=hex:68,61,66,6d,6c,63,65,69,6e,70,
68,69,6f,64,62,66,00,00
"jbdhcgcblljpfglfdephgnjpnamnegmckleaapcbnmmkokjgiamm"=hex:68,61,66,6d,6c,63,
65,69,6e,70,68,69,6f,64,62,66,00,00
"dbdhcgcblljpfglfdephemjljpepbakpamencgme"=hex:62,61,69,69,00,00
.
[HKEY_USERS\S-1-5-21-3279554059-404718991-3174698938-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:59,48,13,55,19,c2,af,86,ee,32,e3,b6,89,2e,90,94,45,eb,8a,7b,c5,91,06,
d3,8d,07,73,b1,5a,9a,9f,37,62,92,7c,26,b1,a3,cd,e4,a5,73,bc,02,5a,e9,16,5b,\
"??"=hex:9e,a1,94,72,a6,d1,69,0b,da,7d,d1,cd,e1,bc,59,a4
.
[HKEY_USERS\S-1-5-21-3279554059-404718991-3174698938-1000\Software\SecuROM\License information*]
"datasecu"=hex:ec,71,9d,47,18,52,12,32,32,02,6d,cb,9d,8c,5e,86,38,85,f0,4b,fe,
58,df,da,4e,d0,fc,cf,c2,bb,1b,79,79,4f,9a,ef,33,c0,70,d9,02,6d,d1,9d,bd,38,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
@DACL=(02 0000)
@="Folder Redirection"
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"DllName"=expand:"fdeploy.dll"
"NoMachinePolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"NoGPOListChanges"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"GenerateGroupPolicy"="GenerateGroupPolicy"
"EventSources"=multi:"(Folder Redirection,Application)\00\00"
"DisplayName"=expand:"@fdeploy.dll,-261"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@DACL=(02 0000)
@="Microsoft Disk Quota"
"DisplayName"=expand:"@%SystemRoot%\\System32\\dskquota.dll,-100"
"NoMachinePolicy"=dword:00000000
"NoUserPolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"RequiresSuccessfulRegistry"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000000
"DllName"=expand:"%SystemRoot%\\System32\\dskquota.dll"
"ProcessGroupPolicy"="ProcessGroupPolicy"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
@DACL=(02 0000)
@="QoS Packet Scheduler"
"DisplayName"=expand:"@gptext.dll,-201"
"ProcessGroupPolicy"="ProcessPSCHEDPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}]
@DACL=(02 0000)
@="Remote Desktop USB Redirection"
"DllName"=expand:"%SystemRoot%\\System32\\TsUsbRedirectionGroupPolicyExtension.dll"
"RequiresSuccessfulRegistry"=dword:00000001
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"NoGPOListChanges"=dword:00000001
"NoUserPolicy"=dword:00000001
"DisplayName"=expand:"@%SystemRoot%\\System32\\TsUsbRedirectionGroupPolicyExtension.dll,-100"
"NoBackgroundPolicy"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93}]
@DACL=(02 0000)
@="Windows Search Group Policy Extension"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"=expand:"%SystemRoot%\\System32\\srchadmin.dll"
"RequiresSuccessfulRegistry"=dword:00000001
"NoSlowLink"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoUserPolicy"=dword:00000000
"NoMachinePolicy"=dword:00000000
"PerUserLocalSettings"=dword:00000000
"EnableAsynchronousProcessing"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{8A28E2C5-8D06-49A4-A08C-632DAA493E17}]
@DACL=(02 0000)
@="Deployed Printer Connections"
"DisplayName"=expand:"@%systemroot%\\system32\\gpprnext.dll,-1"
"DllName"=expand:"%systemroot%\\system32\\gpprnext.dll"
"EnableAsynchronousProcessing"=dword:00000001
"ExtensionEventSource"=""
"GenerateGroupPolicy"="PrinterGenerateGroupPolicy"
"MaxNoGPOListChangesInterval"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000000
"NoMachinePolicy"=dword:00000000
"NoSlowLink"=dword:00000001
"NotifyLinkTransition"=dword:00000000
"NoUserPolicy"=dword:00000000
"PerUserLocalSettings"=dword:00000000
"ProcessGroupPolicy"="PrinterProcessGroupPolicy"
"ProcessGroupPolicyEx"="PrinterProcessGroupPolicyEx"
"RequiresSuccessfulRegistry"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{cdeafc3d-948d-49dd-ab12-e578ba4af7aa}]
@DACL=(02 0000)
@="TCPIP"
"DisplayName"=expand:"@gptext.dll,-204"
"ProcessGroupPolicy"="ProcessTCPIPPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
@DACL=(02 0000)
@="IP Security"
"ProcessGroupPolicyEx"="ProcessIPSECPolicyEx"
"GenerateGroupPolicy"="GenerateIPSECPolicy"
"DllName"=expand:"%SystemRoot%\\System32\\polstore.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000000
"DisplayName"=expand:"@c:\\Windows\\system32\\polstore.dll,-5012"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}]
@DACL=(02 0000)
@="Audit Policy Configuration"
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"DllName"=expand:"auditcse.dll"
"NoUserPolicy"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
"MaxNoGPOListChangesInterval"=dword:000003c0
"ForceRefreshFG"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C}]
@DACL=(02 0000)
@="Enterprise QoS"
"DisplayName"=expand:"@gptext.dll,-203"
"ProcessGroupPolicy"="ProcessEQoSPolicy"
"DllName"=expand:"gptext.dll"
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}]
@DACL=(02 0000)
@="CP"
"DisplayName"=expand:"@gptext.dll,-205"
"ProcessGroupPolicy"="ProcessConnectivityPlatformPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2013-12-31 13:32:27 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-12-31 12:32
.
Před spuštěním: Volných bajtů: 200 672 206 848
Po spuštění: Volných bajtů: 199 947 415 552
.
- - End Of File - - 3F531046305C34E660F07415261B49C5
A36C5E4F47E84449FF07ED3517B43A31