Trojan Downloader Murlo a Misleading.WindowsEnterpriseDefend
Napsal: 28 čer 2010 10:22
Zdravím, prosím o pomoc. Napřed mi iobit 360 našel Misleading.WindowsEnterpriseDefender, Registry Key, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe, 4-29617
Misleading.WindowsEnterpriseDefender, Registry Key, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe, 4-29618 a nejde to smazat. Potom spaware doctor mi našel Trojan Downloader Murlo 22 infekci a
Trojan.Generic 2 hrozby. Po skenu doctora vše zmrzlo, tak jsem ho odinstaloval restartoval pc. Zkoušel jsem RSIT a nejde mi spustit, hlásí mi error. Tak jsem sem dal log z Combofixu. Prosím pomožte mi nevím jak to dostat pryč
ComboFix 10-06-27.03 - JARA_2 28.06.2010 9:47.7.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3071.2080 [GMT 2:00]
Spuštěný z: c:\users\JARA_2\Desktop\ComboFix.exe
* Vytvořen nový Bod Obnovení
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\secushr.dat
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-28 do 2010-06-28 )))))))))))))))))))))))))))))))
.
2010-06-28 07:53 . 2010-06-28 07:54 -------- d-----w- c:\users\JARA_2\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Jara1\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-28 06:54 . 2010-06-28 06:54 -------- d--h--w- c:\temp\dvmexp
2010-06-28 06:54 . 2010-06-28 06:54 -------- d-----w- C:\dvmexp
2010-06-28 06:53 . 2010-06-28 06:53 -------- d-----w- c:\users\JARA_2\AppData\Local\Threat Expert
2010-06-28 06:02 . 2010-01-22 07:56 200144 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\Utility.dll
2010-06-28 06:02 . 2010-01-22 07:56 698320 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\PCTBDUpdate.exe
2010-06-28 06:02 . 2010-01-22 07:56 112592 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
2010-06-28 06:02 . 2010-01-22 07:55 767952 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\BDTSupport.dll
2010-06-28 06:02 . 2010-06-28 06:02 687576 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\unins000.exe
2010-06-28 06:02 . 2010-01-22 07:56 149456 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\SGDetectionTool.dll
2010-06-28 06:02 . 2010-01-22 07:56 567248 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
2010-06-28 06:02 . 2010-01-22 07:56 165840 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\PCTBDRes.dll
2010-06-28 06:02 . 2010-01-22 07:56 1652688 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\PCTBDCore.dll
2010-06-28 06:02 . 2010-01-22 07:55 751544 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\PCTLicReset.dll
2010-06-28 06:02 . 2008-09-26 08:10 640000 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\DbgHelp.dll
2010-06-28 05:59 . 2010-03-15 10:48 211272 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Users\JARA_2\AppData\Local\temp\is-SJPFR.tmp\InnoMonitor.exe
2010-06-28 05:59 . 2009-07-07 10:31 79488 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Users\JARA_2\AppData\Local\temp\is-SJPFR.tmp\gtapi.dll
2010-06-23 02:59 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 02:59 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 02:59 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 02:59 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 02:59 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 02:43 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-06-23 02:43 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-06-23 02:43 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-06-17 05:02 . 2010-06-17 05:02 266240 ------w- c:\windows\Setup1.exe
2010-06-17 05:02 . 2010-06-17 05:02 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-06-15 09:48 . 2010-06-15 09:48 -------- d-----w- c:\program files\CrystalDiskInfo
2010-06-15 08:53 . 2010-06-15 08:53 -------- d-----w- c:\users\JARA_2\AppData\Local\VS Revo Group
2010-06-12 18:35 . 2010-06-12 18:37 -------- d-----w- c:\users\Jara1\AppData\Roaming\Zoner
2010-06-12 18:35 . 2010-06-12 18:35 -------- d-----w- c:\users\Jara1\AppData\Local\Zoner
2010-06-09 18:55 . 2010-06-09 18:55 -------- d-----w- c:\users\JARA_2\AppData\Local\WindowsUpdate
2010-06-09 02:41 . 2010-05-21 05:18 977920 ----a-w- c:\windows\system32\wininet.dll
2010-06-09 02:41 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-09 02:40 . 2010-05-01 14:49 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-06-09 02:40 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-06-09 02:40 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-08 10:11 . 2010-06-08 10:11 -------- d-----w- c:\program files\TNod User & Password Finder
2010-06-02 02:35 . 2010-06-02 02:35 -------- d-----w- c:\users\JARA_2\AppData\Local\http___dennisdel.com
2010-05-30 07:44 . 2009-12-07 07:49 17664 ----a-w- c:\windows\system32\drivers\EnumProcessesDriver.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 06:54 . 2010-03-11 03:49 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin
2010-06-28 06:40 . 2009-08-05 20:01 -------- d-----w- c:\program files\Google
2010-06-28 05:40 . 2010-05-05 17:35 -------- d-----w- c:\users\JARA_2\AppData\Roaming\AIMP
2010-06-27 05:30 . 2009-08-26 09:31 656998 ----a-w- c:\windows\system32\perfh005.dat
2010-06-27 05:30 . 2009-08-26 09:31 136058 ----a-w- c:\windows\system32\perfc005.dat
2010-06-23 07:45 . 2010-01-02 01:24 128056 ----a-w- c:\users\JARA_2\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-21 03:08 . 2009-08-05 19:43 -------- d-----w- c:\programdata\Microsoft Help
2010-06-20 18:28 . 2010-05-13 17:45 -------- d-----w- c:\users\JARA_2\AppData\Roaming\GHISLER
2010-06-20 18:11 . 2009-12-24 05:46 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Ashampoo
2010-06-20 18:10 . 2010-02-21 08:51 -------- d-----w- c:\program files\Ashampoo
2010-06-16 13:48 . 2010-05-05 17:35 -------- d-----w- c:\program files\AIMP2
2010-06-15 09:10 . 2010-01-30 14:53 -------- d-----w- c:\program files\Ultimate Process Manager
2010-06-12 18:35 . 2010-03-05 17:04 130080 ----a-w- c:\users\Jara1\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-10 05:18 . 2010-03-29 07:17 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2010-06-10 05:18 . 2010-03-29 07:17 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2010-06-10 01:46 . 2009-11-24 19:36 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-09 19:03 . 2009-10-22 09:30 -------- d-----w- c:\program files\Microsoft
2010-06-08 08:50 . 2009-10-22 09:27 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-03 17:19 . 2010-03-01 15:01 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Skype
2010-06-03 16:36 . 2010-03-01 15:31 -------- d-----w- c:\users\JARA_2\AppData\Roaming\skypePM
2010-05-30 08:14 . 2010-01-31 04:26 -------- d-----w- c:\program files\CCleaner
2010-05-30 08:00 . 2010-04-13 14:13 -------- d-----w- c:\program files\COMODO
2010-05-29 03:44 . 2010-03-01 11:13 -------- d-----w- c:\users\JARA_2\AppData\Roaming\IObit
2010-05-24 10:05 . 2010-03-04 04:36 -------- d-----w- c:\program files\trend micro
2010-05-24 06:05 . 2009-08-05 19:56 -------- d-----w- c:\program files\Common Files\LightScribe
2010-05-22 20:42 . 2010-05-22 17:43 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Dexpot
2010-05-22 17:35 . 2010-03-19 21:02 -------- d-----w- c:\users\JARA_2\AppData\Roaming\AVI ReComp
2010-05-21 12:14 . 2009-10-31 16:15 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-17 13:06 . 2010-02-07 12:49 -------- d-----w- c:\programdata\ChessBase
2010-05-16 13:05 . 2010-05-16 13:05 -------- d-----w- c:\program files\Common Files\ChessBase
2010-05-16 13:05 . 2010-02-07 12:36 -------- d-----w- c:\program files\ChessBase
2010-05-16 13:02 . 2009-08-05 19:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-16 12:30 . 2010-05-16 12:30 -------- d-----w- c:\program files\DAMN NFO Viewer
2010-05-13 12:33 . 2010-05-10 03:38 -------- d-----w- c:\users\JARA_2\AppData\Roaming\ChessBase
2010-05-12 14:43 . 2010-05-12 14:43 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-05-12 05:47 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-05-10 03:38 . 2010-05-10 03:33 -------- d-----w- c:\program files\Fritz 9
2010-05-09 18:05 . 2009-11-29 23:34 -------- d-----w- c:\program files\Java
2010-05-09 06:01 . 2010-02-07 05:56 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Vso
2010-05-06 15:51 . 2010-05-06 15:40 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Zoner
2010-05-06 15:39 . 2010-05-06 15:39 -------- d-----w- c:\program files\Zoner
2010-05-05 15:52 . 2010-04-01 17:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-02 18:54 . 2010-05-02 18:54 -------- d-----w- c:\users\JARA_2\AppData\Roaming\GRETECH
2010-05-02 18:48 . 2010-05-02 18:48 -------- d-----w- c:\program files\GRETECH
2010-05-01 20:30 . 2010-03-10 13:32 -------- d-----w- c:\programdata\SpeedBit
2010-05-01 17:36 . 2009-08-05 20:01 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-05-01 14:19 . 2010-03-10 13:40 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-05-01 03:58 . 2010-03-06 21:33 -------- d-----w- c:\program files\Opera
2010-04-29 13:39 . 2010-04-01 17:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-04-01 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 07:13 . 2010-05-26 02:40 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-14 07:12 . 2009-08-05 19:56 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-04-14 07:12 . 2009-08-05 19:56 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-04-12 15:29 . 2010-05-09 18:05 411368 ----a-w- c:\windows\system32\deployJava1.dll
2009-04-08 09:31 . 2009-04-08 09:31 106496 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2008-08-11 20:45 . 2008-08-11 20:45 155648 ----a-w- c:\program files\Common Files\MSIactionall.dll
2008-05-22 07:35 . 2008-05-22 07:35 51962 ----a-w- c:\program files\Common Files\banner.jpg
2007-06-12 08:34 . 2007-06-12 08:34 35822 ----a-w- c:\program files\Common Files\ASPG_icon.ico
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"UIWatcher"="c:\program files\Ashampoo\Ashampoo UnInstaller 4\UIWatcher.exe" [2010-01-04 2530648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-02-26 2140880]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0crcnat.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]
backup=c:\windows\pss\FancyStart daemon.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
2009-06-24 11:30 272952 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ADSMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2009-08-05 20:54 47672 ----a-w- c:\windows\AsScrProlog.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSTPE]
2007-10-12 04:44 106496 ----a-w- c:\windows\System32\ASUSTPE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKMEDIA]
2009-08-19 19:31 170624 ----a-w- c:\program files\ASUS\ATK Media\DMedia.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKOSD2]
2009-08-17 08:58 6859392 ----a-w- c:\program files\ASUS\ATKOSD2\ATKOSD2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HControlUser]
2009-06-19 09:29 105016 ----a-w- c:\program files\ASUS\ATK Hotkey\HControlUser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-07-16 11:00 6253088 ----a-w- c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2008-07-16 11:01 1833504 ----a-w- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-08-29 16:11 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-12-06 10:12 1029416 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-06 136176]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
R3 NTProcDrv;Process creation detector for NT.;c:\windows\TEMP\drvB28C.tmp [x]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s816mdfl.sys [2007-06-19 13864]
R3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s816mdm.sys [2007-06-19 107304]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-19 1343400]
S0 EnumProcessesDriver;EnumProcessesDriver;c:\windows\system32\drivers\EnumProcessesDriver.sys [2009-12-07 17664]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15416]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-02-26 114984]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-02-26 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-02-26 810120]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-02-26 41312]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2010-06-11 312152]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S2 MDES;DVM Meta Data Export Service;c:\asus.sys\DVMExportService.exe [2008-10-21 307200]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
S3 SiSGbeLH;SiS191/SiS190 – ovladač NDIS 6.0 zařízení sítě Ethernet;c:\windows\system32\DRIVERS\SiSGB6.sys [2009-07-13 48128]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - cmdGuard
*Deregistered* - cmdHlp
*Deregistered* - inspect
*Deregistered* - sp_rsdrv2
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-06-15 c:\windows\Tasks\At1.job
- c:\windows\system32\Shutdown.exe [2009-07-13 01:14]
2010-06-28 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-04-07 12:11]
2010-06-28 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-04-07 09:03]
2010-06-27 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-04-07 15:20]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-06 16:51]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-06 16:51]
2009-11-25 c:\windows\Tasks\User_Feed_Synchronization-{98EEE44C-6E55-4FD8-900C-1E4FAB2CF1F0}.job
- c:\windows\system32\msfeedssync.exe [2009-07-13 01:14]
2009-11-02 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\program files\Wise Registry Cleaner\WiseRegistryCleaner.exe [2009-12-17 22:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Stahnou vse FlashGet3
IE: Stahnout FlashGet3
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: kuaiche.com\software
TCP: {30DF29B2-9651-40C4-B658-E5BE739701EB} = 10.0.0.138
FF - ProfilePath - c:\users\JARA_2\AppData\Roaming\Mozilla\Firefox\Profiles\zfsqyflc.default\
FF - prefs.js: browser.search.selectedEngine - SluneÄŤnice
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://home.speedbit.com/search.aspx?aff=106&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NTProcDrv]
"ImagePath"="\??\c:\windows\TEMP\drvB28C.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0f,f7,c8,9e,fe,89,41,9e,4c,f1,\
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0f,f7,c8,9e,fe,89,41,9e,4c,f1,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-06-28 09:57:18
ComboFix-quarantined-files.txt 2010-06-28 07:57
ComboFix2.txt 2010-05-24 05:09
ComboFix3.txt 2010-05-19 13:14
ComboFix4.txt 2010-04-09 02:33
ComboFix5.txt 2010-06-28 07:45
Před spuštěním: Volných bajtů: 164 080 222 208
Po spuštění: Volných bajtů: 164 130 283 520
- - End Of File - - 86FB0C1A51CADF14E1A654F7CC66F7FD
Misleading.WindowsEnterpriseDefender, Registry Key, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe, 4-29618 a nejde to smazat. Potom spaware doctor mi našel Trojan Downloader Murlo 22 infekci a
Trojan.Generic 2 hrozby. Po skenu doctora vše zmrzlo, tak jsem ho odinstaloval restartoval pc. Zkoušel jsem RSIT a nejde mi spustit, hlásí mi error. Tak jsem sem dal log z Combofixu. Prosím pomožte mi nevím jak to dostat pryč
ComboFix 10-06-27.03 - JARA_2 28.06.2010 9:47.7.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3071.2080 [GMT 2:00]
Spuštěný z: c:\users\JARA_2\Desktop\ComboFix.exe
* Vytvořen nový Bod Obnovení
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\secushr.dat
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-28 do 2010-06-28 )))))))))))))))))))))))))))))))
.
2010-06-28 07:53 . 2010-06-28 07:54 -------- d-----w- c:\users\JARA_2\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Jara1\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-06-28 07:53 . 2010-06-28 07:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-28 06:54 . 2010-06-28 06:54 -------- d--h--w- c:\temp\dvmexp
2010-06-28 06:54 . 2010-06-28 06:54 -------- d-----w- C:\dvmexp
2010-06-28 06:53 . 2010-06-28 06:53 -------- d-----w- c:\users\JARA_2\AppData\Local\Threat Expert
2010-06-28 06:02 . 2010-01-22 07:56 200144 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\Utility.dll
2010-06-28 06:02 . 2010-01-22 07:56 698320 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\PCTBDUpdate.exe
2010-06-28 06:02 . 2010-01-22 07:56 112592 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
2010-06-28 06:02 . 2010-01-22 07:55 767952 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\BDTSupport.dll
2010-06-28 06:02 . 2010-06-28 06:02 687576 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\unins000.exe
2010-06-28 06:02 . 2010-01-22 07:56 149456 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\SGDetectionTool.dll
2010-06-28 06:02 . 2010-01-22 07:56 567248 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
2010-06-28 06:02 . 2010-01-22 07:56 165840 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\PCTBDRes.dll
2010-06-28 06:02 . 2010-01-22 07:56 1652688 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Windows\PCTBDCore.dll
2010-06-28 06:02 . 2010-01-22 07:55 751544 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\PCTLicReset.dll
2010-06-28 06:02 . 2008-09-26 08:10 640000 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Program Files\Spyware Doctor\BDT\DbgHelp.dll
2010-06-28 05:59 . 2010-03-15 10:48 211272 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Users\JARA_2\AppData\Local\temp\is-SJPFR.tmp\InnoMonitor.exe
2010-06-28 05:59 . 2009-07-07 10:31 79488 ----a-w- c:\programdata\ashampoo\Ashampoo UnInstaller 4\Backup\Spyware Doctor 7_0_UIBak\C\Users\JARA_2\AppData\Local\temp\is-SJPFR.tmp\gtapi.dll
2010-06-23 02:59 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 02:59 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 02:59 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 02:59 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 02:59 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 02:43 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-06-23 02:43 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-06-23 02:43 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-06-17 05:02 . 2010-06-17 05:02 266240 ------w- c:\windows\Setup1.exe
2010-06-17 05:02 . 2010-06-17 05:02 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-06-15 09:48 . 2010-06-15 09:48 -------- d-----w- c:\program files\CrystalDiskInfo
2010-06-15 08:53 . 2010-06-15 08:53 -------- d-----w- c:\users\JARA_2\AppData\Local\VS Revo Group
2010-06-12 18:35 . 2010-06-12 18:37 -------- d-----w- c:\users\Jara1\AppData\Roaming\Zoner
2010-06-12 18:35 . 2010-06-12 18:35 -------- d-----w- c:\users\Jara1\AppData\Local\Zoner
2010-06-09 18:55 . 2010-06-09 18:55 -------- d-----w- c:\users\JARA_2\AppData\Local\WindowsUpdate
2010-06-09 02:41 . 2010-05-21 05:18 977920 ----a-w- c:\windows\system32\wininet.dll
2010-06-09 02:41 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-09 02:40 . 2010-05-01 14:49 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-06-09 02:40 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-06-09 02:40 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-08 10:11 . 2010-06-08 10:11 -------- d-----w- c:\program files\TNod User & Password Finder
2010-06-02 02:35 . 2010-06-02 02:35 -------- d-----w- c:\users\JARA_2\AppData\Local\http___dennisdel.com
2010-05-30 07:44 . 2009-12-07 07:49 17664 ----a-w- c:\windows\system32\drivers\EnumProcessesDriver.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 06:54 . 2010-03-11 03:49 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin
2010-06-28 06:40 . 2009-08-05 20:01 -------- d-----w- c:\program files\Google
2010-06-28 05:40 . 2010-05-05 17:35 -------- d-----w- c:\users\JARA_2\AppData\Roaming\AIMP
2010-06-27 05:30 . 2009-08-26 09:31 656998 ----a-w- c:\windows\system32\perfh005.dat
2010-06-27 05:30 . 2009-08-26 09:31 136058 ----a-w- c:\windows\system32\perfc005.dat
2010-06-23 07:45 . 2010-01-02 01:24 128056 ----a-w- c:\users\JARA_2\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-21 03:08 . 2009-08-05 19:43 -------- d-----w- c:\programdata\Microsoft Help
2010-06-20 18:28 . 2010-05-13 17:45 -------- d-----w- c:\users\JARA_2\AppData\Roaming\GHISLER
2010-06-20 18:11 . 2009-12-24 05:46 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Ashampoo
2010-06-20 18:10 . 2010-02-21 08:51 -------- d-----w- c:\program files\Ashampoo
2010-06-16 13:48 . 2010-05-05 17:35 -------- d-----w- c:\program files\AIMP2
2010-06-15 09:10 . 2010-01-30 14:53 -------- d-----w- c:\program files\Ultimate Process Manager
2010-06-12 18:35 . 2010-03-05 17:04 130080 ----a-w- c:\users\Jara1\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-10 05:18 . 2010-03-29 07:17 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2010-06-10 05:18 . 2010-03-29 07:17 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2010-06-10 01:46 . 2009-11-24 19:36 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-09 19:03 . 2009-10-22 09:30 -------- d-----w- c:\program files\Microsoft
2010-06-08 08:50 . 2009-10-22 09:27 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-03 17:19 . 2010-03-01 15:01 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Skype
2010-06-03 16:36 . 2010-03-01 15:31 -------- d-----w- c:\users\JARA_2\AppData\Roaming\skypePM
2010-05-30 08:14 . 2010-01-31 04:26 -------- d-----w- c:\program files\CCleaner
2010-05-30 08:00 . 2010-04-13 14:13 -------- d-----w- c:\program files\COMODO
2010-05-29 03:44 . 2010-03-01 11:13 -------- d-----w- c:\users\JARA_2\AppData\Roaming\IObit
2010-05-24 10:05 . 2010-03-04 04:36 -------- d-----w- c:\program files\trend micro
2010-05-24 06:05 . 2009-08-05 19:56 -------- d-----w- c:\program files\Common Files\LightScribe
2010-05-22 20:42 . 2010-05-22 17:43 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Dexpot
2010-05-22 17:35 . 2010-03-19 21:02 -------- d-----w- c:\users\JARA_2\AppData\Roaming\AVI ReComp
2010-05-21 12:14 . 2009-10-31 16:15 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-17 13:06 . 2010-02-07 12:49 -------- d-----w- c:\programdata\ChessBase
2010-05-16 13:05 . 2010-05-16 13:05 -------- d-----w- c:\program files\Common Files\ChessBase
2010-05-16 13:05 . 2010-02-07 12:36 -------- d-----w- c:\program files\ChessBase
2010-05-16 13:02 . 2009-08-05 19:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-16 12:30 . 2010-05-16 12:30 -------- d-----w- c:\program files\DAMN NFO Viewer
2010-05-13 12:33 . 2010-05-10 03:38 -------- d-----w- c:\users\JARA_2\AppData\Roaming\ChessBase
2010-05-12 14:43 . 2010-05-12 14:43 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-05-12 05:47 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-05-10 03:38 . 2010-05-10 03:33 -------- d-----w- c:\program files\Fritz 9
2010-05-09 18:05 . 2009-11-29 23:34 -------- d-----w- c:\program files\Java
2010-05-09 06:01 . 2010-02-07 05:56 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Vso
2010-05-06 15:51 . 2010-05-06 15:40 -------- d-----w- c:\users\JARA_2\AppData\Roaming\Zoner
2010-05-06 15:39 . 2010-05-06 15:39 -------- d-----w- c:\program files\Zoner
2010-05-05 15:52 . 2010-04-01 17:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-02 18:54 . 2010-05-02 18:54 -------- d-----w- c:\users\JARA_2\AppData\Roaming\GRETECH
2010-05-02 18:48 . 2010-05-02 18:48 -------- d-----w- c:\program files\GRETECH
2010-05-01 20:30 . 2010-03-10 13:32 -------- d-----w- c:\programdata\SpeedBit
2010-05-01 17:36 . 2009-08-05 20:01 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-05-01 14:19 . 2010-03-10 13:40 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-05-01 03:58 . 2010-03-06 21:33 -------- d-----w- c:\program files\Opera
2010-04-29 13:39 . 2010-04-01 17:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-04-01 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 07:13 . 2010-05-26 02:40 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-14 07:12 . 2009-08-05 19:56 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-04-14 07:12 . 2009-08-05 19:56 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-04-12 15:29 . 2010-05-09 18:05 411368 ----a-w- c:\windows\system32\deployJava1.dll
2009-04-08 09:31 . 2009-04-08 09:31 106496 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2008-08-11 20:45 . 2008-08-11 20:45 155648 ----a-w- c:\program files\Common Files\MSIactionall.dll
2008-05-22 07:35 . 2008-05-22 07:35 51962 ----a-w- c:\program files\Common Files\banner.jpg
2007-06-12 08:34 . 2007-06-12 08:34 35822 ----a-w- c:\program files\Common Files\ASPG_icon.ico
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"UIWatcher"="c:\program files\Ashampoo\Ashampoo UnInstaller 4\UIWatcher.exe" [2010-01-04 2530648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-02-26 2140880]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0crcnat.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]
backup=c:\windows\pss\FancyStart daemon.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
2009-06-24 11:30 272952 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ADSMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2009-08-05 20:54 47672 ----a-w- c:\windows\AsScrProlog.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSTPE]
2007-10-12 04:44 106496 ----a-w- c:\windows\System32\ASUSTPE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKMEDIA]
2009-08-19 19:31 170624 ----a-w- c:\program files\ASUS\ATK Media\DMedia.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKOSD2]
2009-08-17 08:58 6859392 ----a-w- c:\program files\ASUS\ATKOSD2\ATKOSD2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HControlUser]
2009-06-19 09:29 105016 ----a-w- c:\program files\ASUS\ATK Hotkey\HControlUser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-07-16 11:00 6253088 ----a-w- c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2008-07-16 11:01 1833504 ----a-w- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-08-29 16:11 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-12-06 10:12 1029416 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-06 136176]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
R3 NTProcDrv;Process creation detector for NT.;c:\windows\TEMP\drvB28C.tmp [x]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s816mdfl.sys [2007-06-19 13864]
R3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s816mdm.sys [2007-06-19 107304]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-19 1343400]
S0 EnumProcessesDriver;EnumProcessesDriver;c:\windows\system32\drivers\EnumProcessesDriver.sys [2009-12-07 17664]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15416]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-02-26 114984]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-02-26 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-02-26 810120]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-02-26 41312]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2010-06-11 312152]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S2 MDES;DVM Meta Data Export Service;c:\asus.sys\DVMExportService.exe [2008-10-21 307200]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
S3 SiSGbeLH;SiS191/SiS190 – ovladač NDIS 6.0 zařízení sítě Ethernet;c:\windows\system32\DRIVERS\SiSGB6.sys [2009-07-13 48128]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - cmdGuard
*Deregistered* - cmdHlp
*Deregistered* - inspect
*Deregistered* - sp_rsdrv2
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-06-15 c:\windows\Tasks\At1.job
- c:\windows\system32\Shutdown.exe [2009-07-13 01:14]
2010-06-28 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-04-07 12:11]
2010-06-28 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-04-07 09:03]
2010-06-27 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-04-07 15:20]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-06 16:51]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-06 16:51]
2009-11-25 c:\windows\Tasks\User_Feed_Synchronization-{98EEE44C-6E55-4FD8-900C-1E4FAB2CF1F0}.job
- c:\windows\system32\msfeedssync.exe [2009-07-13 01:14]
2009-11-02 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\program files\Wise Registry Cleaner\WiseRegistryCleaner.exe [2009-12-17 22:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Stahnou vse FlashGet3
IE: Stahnout FlashGet3
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: kuaiche.com\software
TCP: {30DF29B2-9651-40C4-B658-E5BE739701EB} = 10.0.0.138
FF - ProfilePath - c:\users\JARA_2\AppData\Roaming\Mozilla\Firefox\Profiles\zfsqyflc.default\
FF - prefs.js: browser.search.selectedEngine - SluneÄŤnice
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://home.speedbit.com/search.aspx?aff=106&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NTProcDrv]
"ImagePath"="\??\c:\windows\TEMP\drvB28C.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0f,f7,c8,9e,fe,89,41,9e,4c,f1,\
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0f,f7,c8,9e,fe,89,41,9e,4c,f1,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-06-28 09:57:18
ComboFix-quarantined-files.txt 2010-06-28 07:57
ComboFix2.txt 2010-05-24 05:09
ComboFix3.txt 2010-05-19 13:14
ComboFix4.txt 2010-04-09 02:33
ComboFix5.txt 2010-06-28 07:45
Před spuštěním: Volných bajtů: 164 080 222 208
Po spuštění: Volných bajtů: 164 130 283 520
- - End Of File - - 86FB0C1A51CADF14E1A654F7CC66F7FD