Kontrola logu
Napsal: 29 pro 2010 18:10
Dobrý den, začal se mi místy "zasekávat systém" a to klidně i na necelou minutu. Po "odhryznuti" se pozmění systémový čas. Projel jsem notas nekolika free programy ale nic neukazaly.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verze databáze: 5416
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
29.12.2010 16:17:45
mbam-log-2010-12-29 (16-17-45).txt
Typ kontroly: Rychlý test
Testované objekty: 153942
Uplynulý čas: 5 minut, 32 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Log z ComboFixu
ComboFix 10-12-28.03 - Antrac1t 29.12.2010 16:39:12.1.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.586 [GMT 1:00]
Spuštěný z: C:\Users\Antrac1t\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Antrac1t\AppData\Roaming\Local
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\.ddr
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\.ddp
C:\Windows\system32\arp.exe . . . . nemohl být smazán
C:\Windows\system32\slwga.dll . . . . nemohl být smazán
C:\Windows\system32\systemcpl.dll . . . . nemohl být smazán
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-28 do 2010-12-29 )))))))))))))))))))))))))))))))
.
2010-12-29 15:49:50 . 2010-12-29 15:49:50 -------- d-----w- C:\Users\Default\AppData\Local\temp
2010-12-29 15:10:46 . 2010-12-20 17:09:00 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-12-29 15:10:45 . 2010-12-29 15:10:45 -------- d-----w- C:\ProgramData\Malwarebytes
2010-12-29 15:10:40 . 2010-12-29 15:10:51 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-12-29 15:01:40 . 2010-12-29 15:01:48 -------- d-----w- C:\Program Files\CCleaner
2010-12-29 12:50:15 . 2010-12-29 12:50:15 143360 ----a-w- C:\vrayspawner2010.exe
2010-12-29 12:50:15 . 2010-12-29 12:50:15 -------- d-----w- C:\defaults
2010-12-29 12:50:14 . 2010-12-29 12:50:14 1101312 ----a-w- C:\dte_wrapper.dll
2010-12-29 12:50:14 . 2010-12-29 12:50:14 1011712 ----a-w- C:\HairVrPrims2010.dll
2010-12-29 12:50:12 . 2010-12-29 12:50:12 7787520 ----a-w- C:\vray2010.dll
2010-12-29 12:50:12 . 2010-12-29 12:50:12 3381944 ----a-w- C:\libmmd.dll
2010-12-29 12:35:16 . 2010-12-29 12:50:00 -------- d-----w- C:\Program Files\Common Files\ChaosGroup
2010-12-29 12:35:09 . 2010-12-29 12:50:13 540672 ----a-w- C:\vrayraw2010.bmi
2010-12-29 12:35:09 . 2010-12-29 12:50:13 4173312 ----a-w- C:\vrender2010.dlr
2010-12-29 12:23:05 . 2009-12-03 05:00:00 344576 ----a-w- C:\Windows\SysWow64\wibuKJni.dll
2010-12-29 12:23:05 . 2009-12-03 05:00:00 333824 ----a-w- C:\Windows\SysWow64\WkExt32.dll
2010-12-29 12:23:05 . 2009-10-21 08:00:00 356352 ----a-w- C:\Windows\SysWow64\WibuXpm4J32.dll
2010-12-29 12:22:25 . 2009-12-03 05:00:00 150528 ----a-w- C:\Windows\SysWow64\WkWin32.dll
2010-12-29 12:22:15 . 2010-12-29 12:22:15 -------- d-----w- C:\Program Files\WIBU-SYSTEMS
2010-12-29 12:22:15 . 2010-12-29 12:22:15 -------- d-----w- C:\Program Files (x86)\WIBUKEY
2010-12-29 12:22:15 . 2010-12-29 12:22:15 -------- d-----w- C:\Program Files (x86)\WIBU-SYSTEMS
2010-12-28 13:01:42 . 2010-12-28 13:01:43 -------- dc-h--w- C:\ProgramData\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
2010-12-28 13:01:18 . 2010-12-28 13:17:29 -------- d-----w- C:\ProgramData\Lavasoft
2010-12-28 13:01:18 . 2010-12-28 13:01:18 -------- d-----w- C:\Program Files (x86)\Lavasoft
2010-12-28 08:10:28 . 2010-11-16 11:01:20 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C361E793-2B27-4336-A057-97FC30F57866}\mpengine.dll
2010-12-26 15:30:41 . 2008-10-10 03:52:38 452440 ----a-w- C:\Windows\SysWow64\d3dx10_40.dll
2010-12-26 15:30:41 . 2008-10-10 03:52:38 4379984 ----a-w- C:\Windows\SysWow64\D3DX9_40.dll
2010-12-26 15:30:41 . 2008-10-10 03:52:38 2036576 ----a-w- C:\Windows\SysWow64\D3DCompiler_40.dll
2010-12-26 15:30:41 . 2007-04-04 17:53:42 81768 ----a-w- C:\Windows\SysWow64\xinput1_3.dll
2010-12-26 11:15:13 . 2010-12-26 11:15:13 -------- d-----w- C:\Program Files (x86)\FreeTime
2010-12-25 16:40:32 . 2010-12-25 16:40:32 -------- d-----w- C:\Program Files (x86)\Aiseesoft Studio
2010-12-25 16:35:55 . 2010-12-25 16:39:01 -------- d-----w- C:\Program Files (x86)\MKVtoolnix
2010-12-25 08:49:32 . 2010-12-25 08:49:32 -------- d-----w- C:\Program Files (x86)\ICQ6Toolbar
2010-12-25 08:49:28 . 2010-12-25 08:49:31 -------- d-----w- C:\ProgramData\ICQ
2010-12-25 08:48:51 . 2010-12-25 08:50:37 -------- d-----w- C:\Program Files (x86)\ICQ7.2
2010-12-19 20:53:15 . 2010-12-19 20:53:15 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2010-12-18 21:14:27 . 2010-12-18 21:14:27 -------- d-----w- C:\Program Files (x86)\Common Files\Skype
2010-12-18 21:14:25 . 2010-12-18 21:14:52 -------- d-----r- C:\Program Files (x86)\Skype
2010-12-18 21:14:20 . 2010-12-18 21:14:23 -------- d-----w- C:\ProgramData\Skype
2010-12-18 21:11:47 . 2010-12-18 21:11:51 -------- d-----w- C:\Program Files\SlikSvn
2010-12-18 21:04:27 . 2010-12-18 21:04:28 -------- d-----w- C:\Program Files (x86)\Sparx Systems
2010-12-18 21:03:17 . 2010-12-18 21:03:17 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2010-12-17 11:40:52 . 2010-12-17 11:41:58 -------- d-----w- C:\Program Files (x86)\TeamSpeak 3 Client
2010-12-17 11:37:28 . 2010-12-17 11:37:28 -------- d-----w- C:\ProgramData\boost_interprocess
2010-12-17 09:11:53 . 2010-12-17 09:13:02 -------- d-----w- C:\Program Files (x86)\glassfish-3.0.1
2010-12-17 09:04:19 . 2010-12-17 09:11:51 -------- d-----w- C:\Program Files (x86)\NetBeans 6.9.1
2010-12-17 08:59:46 . 2010-12-17 09:01:20 -------- d-----w- C:\Program Files\Java
2010-12-15 21:12:45 . 2010-12-15 21:12:45 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2010-12-15 21:12:37 . 2010-12-15 21:12:39 -------- d-----w- C:\Program Files\DivX
2010-12-15 21:12:03 . 2010-12-15 21:12:27 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2010-12-15 21:10:15 . 2010-12-15 21:13:27 -------- d-----w- C:\Program Files (x86)\DivX
2010-12-15 21:08:21 . 2010-12-15 21:13:28 -------- d-----w- C:\ProgramData\DivX
2010-12-15 20:41:24 . 2010-12-15 20:41:24 -------- d-----w- C:\Program Files (x86)\IrfanView
2010-12-15 17:49:06 . 2010-12-16 07:22:46 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2010-12-15 17:49:04 . 2010-12-16 14:07:32 -------- d-----w- C:\Program Files (x86)\Steam
2010-12-15 07:45:20 . 2010-10-27 04:32:36 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2010-12-15 07:45:13 . 2010-11-02 04:40:36 496128 ----a-w- C:\Windows\SysWow64\taskschd.dll
2010-12-15 07:45:13 . 2010-11-02 04:40:36 305152 ----a-w- C:\Windows\SysWow64\taskcomp.dll
2010-12-15 07:45:13 . 2010-11-02 04:34:44 192000 ----a-w- C:\Windows\SysWow64\taskeng.exe
2010-12-15 07:45:13 . 2010-11-02 04:34:33 179712 ----a-w- C:\Windows\SysWow64\schtasks.exe
2010-12-15 07:45:09 . 2010-10-20 04:54:18 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2010-12-15 07:45:09 . 2010-10-20 02:58:41 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll
2010-12-15 07:45:07 . 2010-10-16 04:36:10 314368 ----a-w- C:\Windows\SysWow64\webio.dll
2010-12-15 07:45:06 . 2010-10-12 05:05:01 35328 ----a-w- C:\Program Files\Windows Mail\wabfind.dll
2010-12-15 07:45:06 . 2010-10-12 05:00:30 516096 ----a-w- C:\Program Files\Windows Mail\wab.exe
2010-12-15 07:45:06 . 2010-10-12 04:25:09 516096 ----a-w- C:\Program Files (x86)\Windows Mail\wab.exe
2010-12-14 20:13:30 . 2010-12-14 20:13:30 -------- d-----w- C:\Program Files (x86)\Bonjour
2010-12-14 12:57:26 . 2010-12-14 13:14:54 -------- d-----w- C:\ProgramData\Creative
2010-12-14 12:56:46 . 2003-06-12 22:25:40 7062 ----a-w- C:\Windows\SysWow64\audiopid.vxd
2010-12-14 12:56:13 . 2000-05-22 15:58:00 647872 ------w- C:\Windows\SysWow64\Mscomct2.ocx
2010-12-14 12:56:12 . 2006-10-06 13:17:34 53248 ------w- C:\Windows\Ctregrun.exe
2010-12-14 12:53:00 . 2010-12-14 12:53:00 -------- d-----w- C:\Program Files (x86)\Common Files\Creative
2010-12-14 12:52:55 . 2010-12-14 13:12:15 -------- d--h--w- C:\Program Files (x86)\Creative Installation Information
2010-12-14 12:52:32 . 2008-08-26 08:30:32 8704 ----a-w- C:\Windows\ResDefE.exe
2010-12-14 12:52:28 . 2010-12-14 17:01:57 -------- d-----w- C:\Program Files\Creative
2010-12-14 12:52:27 . 2008-09-10 02:54:34 497152 ----a-r- C:\Windows\SysWow64\CTAPO32.dll
2010-12-14 12:52:22 . 2010-12-14 12:52:22 413696 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2010-12-14 12:52:22 . 2010-12-14 12:52:22 110592 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2010-12-14 12:52:22 . 2007-07-09 02:59:14 782336 ----a-r- C:\Windows\SysWow64\tmp6864.tmp
2010-12-14 12:51:59 . 2010-12-14 12:51:59 -------- d-----w- C:\ProgramData\Creative Labs
2010-12-14 12:50:30 . 2010-12-14 12:50:30 -------- d-----w- C:\Program Files (x86)\Common Files\Creative Labs Shared
2010-12-14 12:49:56 . 2010-12-14 13:13:59 -------- d-----w- C:\Program Files (x86)\Creative
2010-12-14 12:48:25 . 2010-12-25 08:49:29 -------- d--h--w- C:\Program Files (x86)\InstallShield Installation Information
2010-12-14 12:48:20 . 2010-12-14 12:48:20 -------- d-----w- C:\Program Files (x86)\Common Files\InstallShield
2010-12-14 07:28:06 . 2009-09-10 05:52:05 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2010-12-14 07:19:14 . 2010-12-14 07:19:14 -------- d-----w- C:\Windows\SysWow64\Wat
2010-12-13 23:07:17 . 2009-11-25 11:47:34 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2010-12-13 23:07:17 . 2009-11-25 11:47:34 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2010-12-13 23:07:17 . 2009-11-25 11:47:34 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2010-12-13 23:07:17 . 2009-11-25 11:47:34 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2010-12-13 23:07:17 . 2009-11-25 11:47:34 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2010-12-13 20:54:00 . 2010-12-22 18:23:12 -------- d-----w- C:\ProgramData\FLEXnet
2010-12-13 15:47:38 . 2010-12-13 15:47:38 -------- d-----w- C:\ProgramData\NVIDIA
2010-12-13 14:42:22 . 2010-12-13 14:42:22 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2010-12-13 14:41:18 . 2010-12-13 14:41:18 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2010-12-13 14:40:27 . 2010-10-16 18:55:00 57960 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 5473896 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 4837480 ----a-w- C:\Windows\SysWow64\nvcuda.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 319080 ----a-w- C:\Windows\SysWow64\nvdecodemft.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 2912360 ----a-w- C:\Windows\SysWow64\nvcuvid.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 2666600 ----a-w- C:\Windows\SysWow64\nvcuvenc.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 1719912 ----a-w- C:\Windows\SysWow64\nvapi.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 14899816 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 13019752 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 10023528 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2010-12-13 14:39:38 . 2010-12-13 14:41:59 -------- d-----w- C:\Program Files\NVIDIA Corporation
2010-12-13 14:39:11 . 2010-12-13 14:39:11 -------- d-----w- C:\NVIDIA
2010-12-13 04:28:31 . 2010-03-05 07:42:42 67584 ----a-w- C:\Windows\SysWow64\asycfilt.dll
2010-12-13 04:28:27 . 2010-03-24 06:37:04 1289528 ----a-w- C:\Windows\SysWow64\ntdll.dll
2010-12-13 04:28:24 . 2010-03-08 21:33:56 427520 ----a-w- C:\Windows\SysWow64\vbscript.dll
2010-12-13 04:28:23 . 2010-10-19 08:47:59 7680 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2010-12-13 04:28:23 . 2010-10-19 08:10:26 7680 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2010-12-13 04:28:23 . 2010-08-26 04:39:58 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-12-13 04:28:21 . 2010-06-29 05:35:06 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-12-13 04:28:21 . 2010-06-29 05:02:02 1413632 ----a-w- C:\Windows\SysWow64\ole32.dll
2010-12-13 04:28:21 . 2010-06-29 04:57:58 4247040 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-12-13 04:28:19 . 2010-05-05 06:46:55 363520 ----a-w- C:\Windows\SysWow64\StructuredQuery.dll
2010-12-13 04:28:14 . 2009-09-03 07:04:15 1320960 ----a-w- C:\Windows\SysWow64\CertEnroll.dll
2010-12-13 04:26:58 . 2009-12-22 08:24:35 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2010-12-13 04:25:45 . 2010-08-31 04:32:30 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-12-13 04:25:45 . 2010-08-31 04:32:30 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-12-13 04:25:44 . 2009-08-29 06:57:31 34816 ----a-w- C:\Windows\SysWow64\msasn1.dll
2010-12-13 04:25:43 . 2009-10-19 14:10:06 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2010-12-13 04:25:20 . 2010-09-01 05:14:31 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-12-13 04:25:20 . 2010-09-01 04:26:04 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-12 12:50:45 . 2010-12-12 12:50:45 50176 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\tcpip.sys.mui
2010-12-12 12:50:45 . 2010-12-12 12:50:45 27136 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\bfe.dll.mui
2010-12-12 12:50:44 . 2010-12-12 12:50:44 2560 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\scfilter.sys.mui
2010-12-12 12:50:44 . 2010-12-12 12:50:44 2560 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\qwavedrv.sys.mui
2010-12-12 12:50:34 . 2010-12-12 12:50:34 15360 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\pacer.sys.mui
2010-12-12 12:50:31 . 2010-12-12 12:50:31 5632 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\ndiscap.sys.mui
2010-11-12 00:44:54 . 2010-11-12 00:44:54 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
2010-11-08 22:57:04 . 2010-11-08 22:57:04 353592 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2010-11-02 04:34:33 . 2010-12-15 07:45:13 179712 ----a-w- C:\Windows\SysWow64\schtasks.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23:06 1385864 ----a-w- C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll" [2010-05-26 14:23:06 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 94208 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 94208 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 94208 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 11:44:11 85160]
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47:42 31016]
"Acrobat Assistant 7.0"="C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 10:12:02 483328]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 10:44:46 248552]
"VolPanel"="C:\Program Files (x86)\Creative\USB Headsets\Volume Panel\VolPanlu.exe" [2009-07-07 12:13:38 241789]
"DivXUpdate"="C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" [2010-12-09 19:28:24 1226608]
"DivX Download Manager"="C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 21:15:44 63360]
C:\Users\Antrac1t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\Windows\Installer\{AC76BA86-1033-C740-7760-100000000002}\SC_Acrobat.exe [2010-12-12 25214]
Network Server.lnk - C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe [2010-12-29 5724472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 12:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 13:27:14 138576]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-12-14 13:14:09 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-12-14 12:50:30 79360]
R3 GGSAFERDriver;GGSAFER Driver;D:\Garena\safedrv.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2010-12-03 09:05:35 17440]
R3 WatAdminSvc;Služba Technologie aktivace Windows;C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-13 23:05:09 1255736]
S0 Lbd;Lbd;C:\Windows\system32\DRIVERS\Lbd.sys [2010-12-03 09:05:34 69152]
S2 ICQ Service;ICQ Service;C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 17:56:38 247096]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-12-03 09:05:32 1389400]
S2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max Design 2010 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-03-12 16:36:24 86016]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 20:35:28 5434368]
S3 skfiltv;skfiltv;C:\Windows\system32\drivers\skfiltv.sys [2008-08-14 06:48:34 24064]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 21:01:11 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 21:01:11 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 21:01:11 740864]
S3 winbondcir;Winbond IR Transceiver;C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 06:50:18 46592]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 97792 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 97792 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 97792 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = C:\Windows\system32\blank.htm
uStart Page = hxxp://start.icq.com/
mLocal Page = C:\Windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
FF - ProfilePath - C:\Users\Antrac1t\AppData\Roaming\Mozilla\Firefox\Profiles\i18d16ka.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verze databáze: 5416
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
29.12.2010 16:17:45
mbam-log-2010-12-29 (16-17-45).txt
Typ kontroly: Rychlý test
Testované objekty: 153942
Uplynulý čas: 5 minut, 32 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Log z ComboFixu
ComboFix 10-12-28.03 - Antrac1t 29.12.2010 16:39:12.1.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.586 [GMT 1:00]
Spuštěný z: C:\Users\Antrac1t\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Antrac1t\AppData\Roaming\Local
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\.ddr
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
C:\Users\Antrac1t\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\.ddp
C:\Windows\system32\arp.exe . . . . nemohl být smazán
C:\Windows\system32\slwga.dll . . . . nemohl být smazán
C:\Windows\system32\systemcpl.dll . . . . nemohl být smazán
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-28 do 2010-12-29 )))))))))))))))))))))))))))))))
.
2010-12-29 15:49:50 . 2010-12-29 15:49:50 -------- d-----w- C:\Users\Default\AppData\Local\temp
2010-12-29 15:10:46 . 2010-12-20 17:09:00 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-12-29 15:10:45 . 2010-12-29 15:10:45 -------- d-----w- C:\ProgramData\Malwarebytes
2010-12-29 15:10:40 . 2010-12-29 15:10:51 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-12-29 15:01:40 . 2010-12-29 15:01:48 -------- d-----w- C:\Program Files\CCleaner
2010-12-29 12:50:15 . 2010-12-29 12:50:15 143360 ----a-w- C:\vrayspawner2010.exe
2010-12-29 12:50:15 . 2010-12-29 12:50:15 -------- d-----w- C:\defaults
2010-12-29 12:50:14 . 2010-12-29 12:50:14 1101312 ----a-w- C:\dte_wrapper.dll
2010-12-29 12:50:14 . 2010-12-29 12:50:14 1011712 ----a-w- C:\HairVrPrims2010.dll
2010-12-29 12:50:12 . 2010-12-29 12:50:12 7787520 ----a-w- C:\vray2010.dll
2010-12-29 12:50:12 . 2010-12-29 12:50:12 3381944 ----a-w- C:\libmmd.dll
2010-12-29 12:35:16 . 2010-12-29 12:50:00 -------- d-----w- C:\Program Files\Common Files\ChaosGroup
2010-12-29 12:35:09 . 2010-12-29 12:50:13 540672 ----a-w- C:\vrayraw2010.bmi
2010-12-29 12:35:09 . 2010-12-29 12:50:13 4173312 ----a-w- C:\vrender2010.dlr
2010-12-29 12:23:05 . 2009-12-03 05:00:00 344576 ----a-w- C:\Windows\SysWow64\wibuKJni.dll
2010-12-29 12:23:05 . 2009-12-03 05:00:00 333824 ----a-w- C:\Windows\SysWow64\WkExt32.dll
2010-12-29 12:23:05 . 2009-10-21 08:00:00 356352 ----a-w- C:\Windows\SysWow64\WibuXpm4J32.dll
2010-12-29 12:22:25 . 2009-12-03 05:00:00 150528 ----a-w- C:\Windows\SysWow64\WkWin32.dll
2010-12-29 12:22:15 . 2010-12-29 12:22:15 -------- d-----w- C:\Program Files\WIBU-SYSTEMS
2010-12-29 12:22:15 . 2010-12-29 12:22:15 -------- d-----w- C:\Program Files (x86)\WIBUKEY
2010-12-29 12:22:15 . 2010-12-29 12:22:15 -------- d-----w- C:\Program Files (x86)\WIBU-SYSTEMS
2010-12-28 13:01:42 . 2010-12-28 13:01:43 -------- dc-h--w- C:\ProgramData\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
2010-12-28 13:01:18 . 2010-12-28 13:17:29 -------- d-----w- C:\ProgramData\Lavasoft
2010-12-28 13:01:18 . 2010-12-28 13:01:18 -------- d-----w- C:\Program Files (x86)\Lavasoft
2010-12-28 08:10:28 . 2010-11-16 11:01:20 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C361E793-2B27-4336-A057-97FC30F57866}\mpengine.dll
2010-12-26 15:30:41 . 2008-10-10 03:52:38 452440 ----a-w- C:\Windows\SysWow64\d3dx10_40.dll
2010-12-26 15:30:41 . 2008-10-10 03:52:38 4379984 ----a-w- C:\Windows\SysWow64\D3DX9_40.dll
2010-12-26 15:30:41 . 2008-10-10 03:52:38 2036576 ----a-w- C:\Windows\SysWow64\D3DCompiler_40.dll
2010-12-26 15:30:41 . 2007-04-04 17:53:42 81768 ----a-w- C:\Windows\SysWow64\xinput1_3.dll
2010-12-26 11:15:13 . 2010-12-26 11:15:13 -------- d-----w- C:\Program Files (x86)\FreeTime
2010-12-25 16:40:32 . 2010-12-25 16:40:32 -------- d-----w- C:\Program Files (x86)\Aiseesoft Studio
2010-12-25 16:35:55 . 2010-12-25 16:39:01 -------- d-----w- C:\Program Files (x86)\MKVtoolnix
2010-12-25 08:49:32 . 2010-12-25 08:49:32 -------- d-----w- C:\Program Files (x86)\ICQ6Toolbar
2010-12-25 08:49:28 . 2010-12-25 08:49:31 -------- d-----w- C:\ProgramData\ICQ
2010-12-25 08:48:51 . 2010-12-25 08:50:37 -------- d-----w- C:\Program Files (x86)\ICQ7.2
2010-12-19 20:53:15 . 2010-12-19 20:53:15 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2010-12-18 21:14:27 . 2010-12-18 21:14:27 -------- d-----w- C:\Program Files (x86)\Common Files\Skype
2010-12-18 21:14:25 . 2010-12-18 21:14:52 -------- d-----r- C:\Program Files (x86)\Skype
2010-12-18 21:14:20 . 2010-12-18 21:14:23 -------- d-----w- C:\ProgramData\Skype
2010-12-18 21:11:47 . 2010-12-18 21:11:51 -------- d-----w- C:\Program Files\SlikSvn
2010-12-18 21:04:27 . 2010-12-18 21:04:28 -------- d-----w- C:\Program Files (x86)\Sparx Systems
2010-12-18 21:03:17 . 2010-12-18 21:03:17 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2010-12-17 11:40:52 . 2010-12-17 11:41:58 -------- d-----w- C:\Program Files (x86)\TeamSpeak 3 Client
2010-12-17 11:37:28 . 2010-12-17 11:37:28 -------- d-----w- C:\ProgramData\boost_interprocess
2010-12-17 09:11:53 . 2010-12-17 09:13:02 -------- d-----w- C:\Program Files (x86)\glassfish-3.0.1
2010-12-17 09:04:19 . 2010-12-17 09:11:51 -------- d-----w- C:\Program Files (x86)\NetBeans 6.9.1
2010-12-17 08:59:46 . 2010-12-17 09:01:20 -------- d-----w- C:\Program Files\Java
2010-12-15 21:12:45 . 2010-12-15 21:12:45 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2010-12-15 21:12:37 . 2010-12-15 21:12:39 -------- d-----w- C:\Program Files\DivX
2010-12-15 21:12:03 . 2010-12-15 21:12:27 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2010-12-15 21:10:15 . 2010-12-15 21:13:27 -------- d-----w- C:\Program Files (x86)\DivX
2010-12-15 21:08:21 . 2010-12-15 21:13:28 -------- d-----w- C:\ProgramData\DivX
2010-12-15 20:41:24 . 2010-12-15 20:41:24 -------- d-----w- C:\Program Files (x86)\IrfanView
2010-12-15 17:49:06 . 2010-12-16 07:22:46 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2010-12-15 17:49:04 . 2010-12-16 14:07:32 -------- d-----w- C:\Program Files (x86)\Steam
2010-12-15 07:45:20 . 2010-10-27 04:32:36 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2010-12-15 07:45:13 . 2010-11-02 04:40:36 496128 ----a-w- C:\Windows\SysWow64\taskschd.dll
2010-12-15 07:45:13 . 2010-11-02 04:40:36 305152 ----a-w- C:\Windows\SysWow64\taskcomp.dll
2010-12-15 07:45:13 . 2010-11-02 04:34:44 192000 ----a-w- C:\Windows\SysWow64\taskeng.exe
2010-12-15 07:45:13 . 2010-11-02 04:34:33 179712 ----a-w- C:\Windows\SysWow64\schtasks.exe
2010-12-15 07:45:09 . 2010-10-20 04:54:18 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2010-12-15 07:45:09 . 2010-10-20 02:58:41 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll
2010-12-15 07:45:07 . 2010-10-16 04:36:10 314368 ----a-w- C:\Windows\SysWow64\webio.dll
2010-12-15 07:45:06 . 2010-10-12 05:05:01 35328 ----a-w- C:\Program Files\Windows Mail\wabfind.dll
2010-12-15 07:45:06 . 2010-10-12 05:00:30 516096 ----a-w- C:\Program Files\Windows Mail\wab.exe
2010-12-15 07:45:06 . 2010-10-12 04:25:09 516096 ----a-w- C:\Program Files (x86)\Windows Mail\wab.exe
2010-12-14 20:13:30 . 2010-12-14 20:13:30 -------- d-----w- C:\Program Files (x86)\Bonjour
2010-12-14 12:57:26 . 2010-12-14 13:14:54 -------- d-----w- C:\ProgramData\Creative
2010-12-14 12:56:46 . 2003-06-12 22:25:40 7062 ----a-w- C:\Windows\SysWow64\audiopid.vxd
2010-12-14 12:56:13 . 2000-05-22 15:58:00 647872 ------w- C:\Windows\SysWow64\Mscomct2.ocx
2010-12-14 12:56:12 . 2006-10-06 13:17:34 53248 ------w- C:\Windows\Ctregrun.exe
2010-12-14 12:53:00 . 2010-12-14 12:53:00 -------- d-----w- C:\Program Files (x86)\Common Files\Creative
2010-12-14 12:52:55 . 2010-12-14 13:12:15 -------- d--h--w- C:\Program Files (x86)\Creative Installation Information
2010-12-14 12:52:32 . 2008-08-26 08:30:32 8704 ----a-w- C:\Windows\ResDefE.exe
2010-12-14 12:52:28 . 2010-12-14 17:01:57 -------- d-----w- C:\Program Files\Creative
2010-12-14 12:52:27 . 2008-09-10 02:54:34 497152 ----a-r- C:\Windows\SysWow64\CTAPO32.dll
2010-12-14 12:52:22 . 2010-12-14 12:52:22 413696 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2010-12-14 12:52:22 . 2010-12-14 12:52:22 110592 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2010-12-14 12:52:22 . 2007-07-09 02:59:14 782336 ----a-r- C:\Windows\SysWow64\tmp6864.tmp
2010-12-14 12:51:59 . 2010-12-14 12:51:59 -------- d-----w- C:\ProgramData\Creative Labs
2010-12-14 12:50:30 . 2010-12-14 12:50:30 -------- d-----w- C:\Program Files (x86)\Common Files\Creative Labs Shared
2010-12-14 12:49:56 . 2010-12-14 13:13:59 -------- d-----w- C:\Program Files (x86)\Creative
2010-12-14 12:48:25 . 2010-12-25 08:49:29 -------- d--h--w- C:\Program Files (x86)\InstallShield Installation Information
2010-12-14 12:48:20 . 2010-12-14 12:48:20 -------- d-----w- C:\Program Files (x86)\Common Files\InstallShield
2010-12-14 07:28:06 . 2009-09-10 05:52:05 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2010-12-14 07:19:14 . 2010-12-14 07:19:14 -------- d-----w- C:\Windows\SysWow64\Wat
2010-12-13 23:07:17 . 2009-11-25 11:47:34 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2010-12-13 23:07:17 . 2009-11-25 11:47:34 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2010-12-13 23:07:17 . 2009-11-25 11:47:34 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2010-12-13 23:07:17 . 2009-11-25 11:47:34 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2010-12-13 23:07:17 . 2009-11-25 11:47:34 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2010-12-13 20:54:00 . 2010-12-22 18:23:12 -------- d-----w- C:\ProgramData\FLEXnet
2010-12-13 15:47:38 . 2010-12-13 15:47:38 -------- d-----w- C:\ProgramData\NVIDIA
2010-12-13 14:42:22 . 2010-12-13 14:42:22 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2010-12-13 14:41:18 . 2010-12-13 14:41:18 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2010-12-13 14:40:27 . 2010-10-16 18:55:00 57960 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 5473896 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 4837480 ----a-w- C:\Windows\SysWow64\nvcuda.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 319080 ----a-w- C:\Windows\SysWow64\nvdecodemft.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 2912360 ----a-w- C:\Windows\SysWow64\nvcuvid.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 2666600 ----a-w- C:\Windows\SysWow64\nvcuvenc.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 1719912 ----a-w- C:\Windows\SysWow64\nvapi.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 14899816 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 13019752 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
2010-12-13 14:40:27 . 2010-10-16 18:55:00 10023528 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2010-12-13 14:39:38 . 2010-12-13 14:41:59 -------- d-----w- C:\Program Files\NVIDIA Corporation
2010-12-13 14:39:11 . 2010-12-13 14:39:11 -------- d-----w- C:\NVIDIA
2010-12-13 04:28:31 . 2010-03-05 07:42:42 67584 ----a-w- C:\Windows\SysWow64\asycfilt.dll
2010-12-13 04:28:27 . 2010-03-24 06:37:04 1289528 ----a-w- C:\Windows\SysWow64\ntdll.dll
2010-12-13 04:28:24 . 2010-03-08 21:33:56 427520 ----a-w- C:\Windows\SysWow64\vbscript.dll
2010-12-13 04:28:23 . 2010-10-19 08:47:59 7680 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2010-12-13 04:28:23 . 2010-10-19 08:10:26 7680 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2010-12-13 04:28:23 . 2010-08-26 04:39:58 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-12-13 04:28:21 . 2010-06-29 05:35:06 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-12-13 04:28:21 . 2010-06-29 05:02:02 1413632 ----a-w- C:\Windows\SysWow64\ole32.dll
2010-12-13 04:28:21 . 2010-06-29 04:57:58 4247040 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-12-13 04:28:19 . 2010-05-05 06:46:55 363520 ----a-w- C:\Windows\SysWow64\StructuredQuery.dll
2010-12-13 04:28:14 . 2009-09-03 07:04:15 1320960 ----a-w- C:\Windows\SysWow64\CertEnroll.dll
2010-12-13 04:26:58 . 2009-12-22 08:24:35 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2010-12-13 04:25:45 . 2010-08-31 04:32:30 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-12-13 04:25:45 . 2010-08-31 04:32:30 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-12-13 04:25:44 . 2009-08-29 06:57:31 34816 ----a-w- C:\Windows\SysWow64\msasn1.dll
2010-12-13 04:25:43 . 2009-10-19 14:10:06 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2010-12-13 04:25:20 . 2010-09-01 05:14:31 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-12-13 04:25:20 . 2010-09-01 04:26:04 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-12 12:50:45 . 2010-12-12 12:50:45 50176 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\tcpip.sys.mui
2010-12-12 12:50:45 . 2010-12-12 12:50:45 27136 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\bfe.dll.mui
2010-12-12 12:50:44 . 2010-12-12 12:50:44 2560 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\scfilter.sys.mui
2010-12-12 12:50:44 . 2010-12-12 12:50:44 2560 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\qwavedrv.sys.mui
2010-12-12 12:50:34 . 2010-12-12 12:50:34 15360 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\pacer.sys.mui
2010-12-12 12:50:31 . 2010-12-12 12:50:31 5632 ----a-w- C:\Windows\SysWow64\drivers\cs-CZ\ndiscap.sys.mui
2010-11-12 00:44:54 . 2010-11-12 00:44:54 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
2010-11-08 22:57:04 . 2010-11-08 22:57:04 353592 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
2010-11-02 04:34:33 . 2010-12-15 07:45:13 179712 ----a-w- C:\Windows\SysWow64\schtasks.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23:06 1385864 ----a-w- C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll" [2010-05-26 14:23:06 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 94208 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 94208 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 94208 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 11:44:11 85160]
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47:42 31016]
"Acrobat Assistant 7.0"="C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 10:12:02 483328]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 10:44:46 248552]
"VolPanel"="C:\Program Files (x86)\Creative\USB Headsets\Volume Panel\VolPanlu.exe" [2009-07-07 12:13:38 241789]
"DivXUpdate"="C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" [2010-12-09 19:28:24 1226608]
"DivX Download Manager"="C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 21:15:44 63360]
C:\Users\Antrac1t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\Windows\Installer\{AC76BA86-1033-C740-7760-100000000002}\SC_Acrobat.exe [2010-12-12 25214]
Network Server.lnk - C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe [2010-12-29 5724472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 12:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 13:27:14 138576]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-12-14 13:14:09 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-12-14 12:50:30 79360]
R3 GGSAFERDriver;GGSAFER Driver;D:\Garena\safedrv.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2010-12-03 09:05:35 17440]
R3 WatAdminSvc;Služba Technologie aktivace Windows;C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-13 23:05:09 1255736]
S0 Lbd;Lbd;C:\Windows\system32\DRIVERS\Lbd.sys [2010-12-03 09:05:34 69152]
S2 ICQ Service;ICQ Service;C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 17:56:38 247096]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-12-03 09:05:32 1389400]
S2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max Design 2010 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-03-12 16:36:24 86016]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 20:35:28 5434368]
S3 skfiltv;skfiltv;C:\Windows\system32\drivers\skfiltv.sys [2008-08-14 06:48:34 24064]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 21:01:11 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 21:01:11 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 21:01:11 740864]
S3 winbondcir;Winbond IR Transceiver;C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 06:50:18 46592]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 97792 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 97792 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19:44 97792 ----a-w- C:\Users\Antrac1t\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = C:\Windows\system32\blank.htm
uStart Page = hxxp://start.icq.com/
mLocal Page = C:\Windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
FF - ProfilePath - C:\Users\Antrac1t\AppData\Roaming\Mozilla\Firefox\Profiles\i18d16ka.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)