Re: PC jede na 100%, objevil se vir Policie ČR
Napsal: 15 úno 2014 18:37
Zoek.exe v5.0.0.0 Updated 15-February-2014
Tool run by Administrator on so 15.02.2014 at 16:10:36,60.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\Administrator\Plocha\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
15.2.2014 16:11:47 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Creating Sample_15.02.2014_1617.zip ======================
C:\Documents and Settings\All Users\Plocha\sample_15.02.2014_1617.zip created successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\jqs@sun.com deleted successfully
==== Running Processes ======================
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\SecretSauce\updateSecretSauce.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SecretSauce\bin\utilSecretSauce.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe
C:\Documents and Settings\Administrator\Data aplikací\System.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\FaceBookHacker.exe
C:\Documents and Settings\Administrator\Plocha\zoek.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Update SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Update SecretSauce deleted successfully
==== Deleting Files \ Folders ======================
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Adobe not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3 not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Alternative Software Ltd not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\ashampoo not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Atheros not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\ATI not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\AVAST Software not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Big Fish Games not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\BigFishGamesCache not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\BioWare not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Cyberlink not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\dingogames not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\DVD Shrink not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\EA Core not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Electronic Arts not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Malwarebytes not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Malwarebytes' Anti-Malware (portable) not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\McAfee not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Media Center Programs not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Microsoft not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Microsoft Games not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Microsoft Help not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\MicroWorld not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\MumboJumbo not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\PMB Files not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Real not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Skype not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Solidshield not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Sun not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\TEMP not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\TP-LINK not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\TrackMania not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\vsosdk not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage not found
C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe.tmp not found
C:\Documents and Settings\Administrator\Data aplikací\System.exe.tmp not found
C:\Documents and Settings\Jan Kubesa\Data aplikací\dach100.dll not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\gauswqussd.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\knphxyhaar.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\nzfqtgxiuu.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\rswfguhvuz.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp62.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp67.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp68.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp6E.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp6F.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmpAD.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\wyfhxjicra.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\xaioytkasp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\xjvlxdcaay.vbs not found
C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe not found
C:\Documents and Settings\Administrator\Data aplikací\System.exe not found
C:\Documents and Settings\Jan Kubesa\Data aplikací\PnkBstrB.exe not found
"C:\Documents and Settings\Administrator\Data aplikací\ATI" not found
"C:\Documents and Settings\Administrator\Data aplikací\Sun" not found
"C:\Documents and Settings\Administrator\Data aplikací\Vso" not found
"C:\Documents and Settings\Administrator\Data aplikací\DivX" not found
"C:\Documents and Settings\Administrator\Data aplikací\Games" not found
"C:\Documents and Settings\Administrator\Data aplikací\SPORE" not found
"C:\Documents and Settings\Administrator\Data aplikací\Unity" not found
"C:\Documents and Settings\Administrator\Data aplikací\CLOUDY" not found
"C:\Documents and Settings\Administrator\Data aplikací\SecuROM" not found
C:\Program Files\ZoneAlarm_Security deleted
C:\Program Files\Free Download Manager deleted
"C:\Program Files\SecretSauce\updateSecretSauce.exe" deleted
"C:\Program Files\SecretSauce\updateSecretSauce.exe" deleted
"C:\Program Files\SecretSauce\bin\utilSecretSauce.exe" deleted
"C:\Program Files\SecretSauce\bin\utilSecretSauce.exe" deleted
"C:\Program Files\SecretSauce" not deleted
"C:\Program Files\SecretSauce" not deleted
"C:\Program Files\SecretSauce\bin" not deleted
"C:\Program Files\SecretSauce\bin" not deleted
======== System Restore Points ========
RP78: 11.2.2014 18:17:39 - ComboFix created restore point
RP79: 13.2.2014 15:51:47 - OTM Restore Point
RP80: 15.2.2014 16:11:47 - zoek.exe restore point
==== Firefox Extensions ======================
AppDir: C:\Program Files\Mozilla Firefox
- Talkback - %AppDir%\extensions\talkback@mozilla.org
- Firefox default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
==== Firefox Plugins ======================
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dbpebffoameokfhnaaedmefjncfboino - C:\Program Files\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx[]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dbpebffoameokfhnaaedmefjncfboino deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 deleted successfully
==== HijackThis Entries ======================
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [tmp67] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp67.tmp.vbs"
O4 - HKLM\..\Run: [rswfguhvuz] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rswfguhvuz.vbs"
O4 - HKLM\..\Run: [knphxyhaar] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\knphxyhaar.vbs"
O4 - HKLM\..\Run: [xjvlxdcaay] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xjvlxdcaay.vbs"
O4 - HKLM\..\Run: [xaioytkasp] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xaioytkasp.vbs"
O4 - HKLM\..\Run: [tmp6E] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6E.tmp.vbs"
O4 - HKLM\..\Run: [tmp62] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp62.tmp.vbs"
O4 - HKLM\..\Run: [tmp68] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp68.tmp.vbs"
O4 - HKLM\..\Run: [tmp6F] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6F.tmp.vbs"
O4 - HKLM\..\Run: [gauswqussd] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gauswqussd.vbs"
O4 - HKLM\..\Run: [nzfqtgxiuu] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzfqtgxiuu.vbs"
O4 - HKLM\..\Run: [tmpAD] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAD.tmp.vbs"
O4 - HKLM\..\Run: [wyfhxjicra] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wyfhxjicra.vbs"
O4 - HKLM\..\Run: [f7f31eeefe847941e67af1a39aae51fc] "C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe" ..
O4 - HKLM\..\Run: [5f805e177fa7c673482c92c255460b67] "C:\Documents and Settings\Administrator\Data aplikací\System.exe" ..
O4 - HKLM\..\Run: [84ed770416516c521a5ceebcdbdcddc5] "C:\Documents and Settings\Administrator\Local Settings\Temp\FaceBookHacker.exe" ..
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [RGSC] E:\Games\GTA_IV\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [tmp67] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp67.tmp.vbs"
O4 - HKCU\..\Run: [rswfguhvuz] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rswfguhvuz.vbs"
O4 - HKCU\..\Run: [knphxyhaar] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\knphxyhaar.vbs"
O4 - HKCU\..\Run: [xjvlxdcaay] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xjvlxdcaay.vbs"
O4 - HKCU\..\Run: [xaioytkasp] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xaioytkasp.vbs"
O4 - HKCU\..\Run: [tmp6E] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6E.tmp.vbs"
O4 - HKCU\..\Run: [tmp62] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp62.tmp.vbs"
O4 - HKCU\..\Run: [tmp68] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp68.tmp.vbs"
O4 - HKCU\..\Run: [tmp6F] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6F.tmp.vbs"
O4 - HKCU\..\Run: [gauswqussd] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gauswqussd.vbs"
O4 - HKCU\..\Run: [nzfqtgxiuu] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzfqtgxiuu.vbs"
O4 - HKCU\..\Run: [tmpAD] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAD.tmp.vbs"
O4 - HKCU\..\Run: [wyfhxjicra] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wyfhxjicra.vbs"
O4 - HKCU\..\Run: [f7f31eeefe847941e67af1a39aae51fc] "C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe" ..
O4 - HKCU\..\Run: [5f805e177fa7c673482c92c255460b67] "C:\Documents and Settings\Administrator\Data aplikací\System.exe" ..
O4 - HKCU\..\Run: [84ed770416516c521a5ceebcdbdcddc5] "C:\Documents and Settings\Administrator\Local Settings\Temp\FaceBookHacker.exe" ..
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: 5f805e177fa7c673482c92c255460b67.exe
O4 - Startup: 84ed770416516c521a5ceebcdbdcddc5.exe
O4 - Startup: f7f31eeefe847941e67af1a39aae51fc.exe
O4 - Startup: gauswqussd.vbs
O4 - Startup: knphxyhaar.vbs
O4 - Startup: nzfqtgxiuu.vbs
O4 - Startup: rswfguhvuz.vbs
O4 - Startup: tmp62.tmp.vbs
O4 - Startup: tmp67.tmp.vbs
O4 - Startup: tmp68.tmp.vbs
O4 - Startup: tmp6E.tmp.vbs
O4 - Startup: tmp6F.tmp.vbs
O4 - Startup: tmpAD.tmp.vbs
O4 - Startup: wyfhxjicra.vbs
O4 - Startup: xaioytkasp.vbs
O4 - Startup: xjvlxdcaay.vbs
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Stáhnout všechny FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\AutoCAD 2002 Cz\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file://C:\Program Files\AutoCAD 2002 Cz\AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002 Cz\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file://C:\Program Files\AutoCAD 2002 Cz\AcPreview.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
==== Empty IE Cache ======================
C:\Documents and Settings\Administrator\Local Settings\temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=9 folders=8 1549439 bytes)
==== Empty Temp Folders ======================
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\RECYCLER successfully emptied
==== Deleting Files / Folders ======================
"C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Program Files\SecretSauce" not found
"C:\Program Files\SecretSauce" not found
==== EOF on so 15.02.2014 at 18:24:15,07 ======================
Tool run by Administrator on so 15.02.2014 at 16:10:36,60.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\Administrator\Plocha\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
15.2.2014 16:11:47 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Creating Sample_15.02.2014_1617.zip ======================
C:\Documents and Settings\All Users\Plocha\sample_15.02.2014_1617.zip created successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-2052111302-1844237615-725345543-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\jqs@sun.com deleted successfully
==== Running Processes ======================
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\SecretSauce\updateSecretSauce.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SecretSauce\bin\utilSecretSauce.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe
C:\Documents and Settings\Administrator\Data aplikací\System.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\FaceBookHacker.exe
C:\Documents and Settings\Administrator\Plocha\zoek.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Util SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Update SecretSauce deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Update SecretSauce deleted successfully
==== Deleting Files \ Folders ======================
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Adobe not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3 not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Alternative Software Ltd not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\ashampoo not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Atheros not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\ATI not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\AVAST Software not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Big Fish Games not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\BigFishGamesCache not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\BioWare not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Cyberlink not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\dingogames not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\DVD Shrink not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\EA Core not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Electronic Arts not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Malwarebytes not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Malwarebytes' Anti-Malware (portable) not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\McAfee not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Media Center Programs not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Microsoft not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Microsoft Games not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Microsoft Help not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\MicroWorld not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\MumboJumbo not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\PMB Files not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Real not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Skype not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Solidshield not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Sun not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\TEMP not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\TP-LINK not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\TrackMania not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\vsosdk not found
C:\Documents and Settings\All Users\Data aplikacˇ\C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage not found
C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe.tmp not found
C:\Documents and Settings\Administrator\Data aplikací\System.exe.tmp not found
C:\Documents and Settings\Jan Kubesa\Data aplikací\dach100.dll not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\gauswqussd.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\knphxyhaar.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\nzfqtgxiuu.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\rswfguhvuz.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp62.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp67.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp68.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp6E.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmp6F.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\tmpAD.tmp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\wyfhxjicra.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\xaioytkasp.vbs not found
C:\DOCUME~1\ADMINI~1\NABDKA~1\Programy\Po spuštění\xjvlxdcaay.vbs not found
C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe not found
C:\Documents and Settings\Administrator\Data aplikací\System.exe not found
C:\Documents and Settings\Jan Kubesa\Data aplikací\PnkBstrB.exe not found
"C:\Documents and Settings\Administrator\Data aplikací\ATI" not found
"C:\Documents and Settings\Administrator\Data aplikací\Sun" not found
"C:\Documents and Settings\Administrator\Data aplikací\Vso" not found
"C:\Documents and Settings\Administrator\Data aplikací\DivX" not found
"C:\Documents and Settings\Administrator\Data aplikací\Games" not found
"C:\Documents and Settings\Administrator\Data aplikací\SPORE" not found
"C:\Documents and Settings\Administrator\Data aplikací\Unity" not found
"C:\Documents and Settings\Administrator\Data aplikací\CLOUDY" not found
"C:\Documents and Settings\Administrator\Data aplikací\SecuROM" not found
C:\Program Files\ZoneAlarm_Security deleted
C:\Program Files\Free Download Manager deleted
"C:\Program Files\SecretSauce\updateSecretSauce.exe" deleted
"C:\Program Files\SecretSauce\updateSecretSauce.exe" deleted
"C:\Program Files\SecretSauce\bin\utilSecretSauce.exe" deleted
"C:\Program Files\SecretSauce\bin\utilSecretSauce.exe" deleted
"C:\Program Files\SecretSauce" not deleted
"C:\Program Files\SecretSauce" not deleted
"C:\Program Files\SecretSauce\bin" not deleted
"C:\Program Files\SecretSauce\bin" not deleted
======== System Restore Points ========
RP78: 11.2.2014 18:17:39 - ComboFix created restore point
RP79: 13.2.2014 15:51:47 - OTM Restore Point
RP80: 15.2.2014 16:11:47 - zoek.exe restore point
==== Firefox Extensions ======================
AppDir: C:\Program Files\Mozilla Firefox
- Talkback - %AppDir%\extensions\talkback@mozilla.org
- Firefox default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
==== Firefox Plugins ======================
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dbpebffoameokfhnaaedmefjncfboino - C:\Program Files\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx[]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dbpebffoameokfhnaaedmefjncfboino deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 deleted successfully
==== HijackThis Entries ======================
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [tmp67] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp67.tmp.vbs"
O4 - HKLM\..\Run: [rswfguhvuz] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rswfguhvuz.vbs"
O4 - HKLM\..\Run: [knphxyhaar] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\knphxyhaar.vbs"
O4 - HKLM\..\Run: [xjvlxdcaay] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xjvlxdcaay.vbs"
O4 - HKLM\..\Run: [xaioytkasp] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xaioytkasp.vbs"
O4 - HKLM\..\Run: [tmp6E] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6E.tmp.vbs"
O4 - HKLM\..\Run: [tmp62] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp62.tmp.vbs"
O4 - HKLM\..\Run: [tmp68] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp68.tmp.vbs"
O4 - HKLM\..\Run: [tmp6F] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6F.tmp.vbs"
O4 - HKLM\..\Run: [gauswqussd] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gauswqussd.vbs"
O4 - HKLM\..\Run: [nzfqtgxiuu] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzfqtgxiuu.vbs"
O4 - HKLM\..\Run: [tmpAD] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAD.tmp.vbs"
O4 - HKLM\..\Run: [wyfhxjicra] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wyfhxjicra.vbs"
O4 - HKLM\..\Run: [f7f31eeefe847941e67af1a39aae51fc] "C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe" ..
O4 - HKLM\..\Run: [5f805e177fa7c673482c92c255460b67] "C:\Documents and Settings\Administrator\Data aplikací\System.exe" ..
O4 - HKLM\..\Run: [84ed770416516c521a5ceebcdbdcddc5] "C:\Documents and Settings\Administrator\Local Settings\Temp\FaceBookHacker.exe" ..
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [RGSC] E:\Games\GTA_IV\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [tmp67] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp67.tmp.vbs"
O4 - HKCU\..\Run: [rswfguhvuz] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rswfguhvuz.vbs"
O4 - HKCU\..\Run: [knphxyhaar] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\knphxyhaar.vbs"
O4 - HKCU\..\Run: [xjvlxdcaay] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xjvlxdcaay.vbs"
O4 - HKCU\..\Run: [xaioytkasp] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xaioytkasp.vbs"
O4 - HKCU\..\Run: [tmp6E] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6E.tmp.vbs"
O4 - HKCU\..\Run: [tmp62] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp62.tmp.vbs"
O4 - HKCU\..\Run: [tmp68] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp68.tmp.vbs"
O4 - HKCU\..\Run: [tmp6F] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6F.tmp.vbs"
O4 - HKCU\..\Run: [gauswqussd] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gauswqussd.vbs"
O4 - HKCU\..\Run: [nzfqtgxiuu] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nzfqtgxiuu.vbs"
O4 - HKCU\..\Run: [tmpAD] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpAD.tmp.vbs"
O4 - HKCU\..\Run: [wyfhxjicra] wscript.exe //B "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wyfhxjicra.vbs"
O4 - HKCU\..\Run: [f7f31eeefe847941e67af1a39aae51fc] "C:\Documents and Settings\Administrator\Data aplikací\32-bit.exe" ..
O4 - HKCU\..\Run: [5f805e177fa7c673482c92c255460b67] "C:\Documents and Settings\Administrator\Data aplikací\System.exe" ..
O4 - HKCU\..\Run: [84ed770416516c521a5ceebcdbdcddc5] "C:\Documents and Settings\Administrator\Local Settings\Temp\FaceBookHacker.exe" ..
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: 5f805e177fa7c673482c92c255460b67.exe
O4 - Startup: 84ed770416516c521a5ceebcdbdcddc5.exe
O4 - Startup: f7f31eeefe847941e67af1a39aae51fc.exe
O4 - Startup: gauswqussd.vbs
O4 - Startup: knphxyhaar.vbs
O4 - Startup: nzfqtgxiuu.vbs
O4 - Startup: rswfguhvuz.vbs
O4 - Startup: tmp62.tmp.vbs
O4 - Startup: tmp67.tmp.vbs
O4 - Startup: tmp68.tmp.vbs
O4 - Startup: tmp6E.tmp.vbs
O4 - Startup: tmp6F.tmp.vbs
O4 - Startup: tmpAD.tmp.vbs
O4 - Startup: wyfhxjicra.vbs
O4 - Startup: xaioytkasp.vbs
O4 - Startup: xjvlxdcaay.vbs
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Stáhnout všechny FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\AutoCAD 2002 Cz\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file://C:\Program Files\AutoCAD 2002 Cz\AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002 Cz\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file://C:\Program Files\AutoCAD 2002 Cz\AcPreview.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
==== Empty IE Cache ======================
C:\Documents and Settings\Administrator\Local Settings\temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=9 folders=8 1549439 bytes)
==== Empty Temp Folders ======================
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\RECYCLER successfully emptied
==== Deleting Files / Folders ======================
"C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Program Files\SecretSauce" not found
"C:\Program Files\SecretSauce" not found
==== EOF on so 15.02.2014 at 18:24:15,07 ======================