Nelze spustis antivir ani IE
Napsal: 23 čer 2011 10:35
Ahoj, prosim o pomoc mam problem nelze mi spustit IE a ani antivir, po pokusi preinstalovat ho mi napise "Sluzba ESET service (ekrn) nelze spustit. Presvedcte se, zda mate dostatecna opravneni pro spousteni systemovych sluzeb".
tady je log z combofixu:
ComboFix 11-06-22.03 - Lada 23.06.2011 10:50:50.1.1 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2048.903 [GMT 2:00]
Spuštěný z: c:\users\Lada\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-05-23 do 2011-06-23 )))))))))))))))))))))))))))))))
.
.
2011-06-23 09:02 . 2011-06-23 09:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-22 10:57 . 2011-06-20 06:57 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F49F1C9F-B20F-4C77-B173-D5D2F6AE7446}\mpengine.dll
2011-06-19 11:59 . 2011-06-22 11:28 -------- d-----w- C:\8ffc7fd40e86cbff785c20b3ceff0383
2011-06-16 08:11 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-16 08:11 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 08:11 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-16 08:09 . 2010-12-18 05:31 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-16 08:08 . 2011-04-27 02:33 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-16 08:08 . 2011-04-25 04:56 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-16 08:08 . 2011-04-25 02:35 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-16 08:08 . 2011-04-29 02:57 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-16 08:08 . 2011-04-29 02:57 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-16 08:08 . 2011-04-29 02:57 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-16 08:08 . 2011-05-03 04:50 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-16 08:08 . 2011-05-04 02:43 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 08:08 . 2011-05-04 02:43 96256 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 08:08 . 2011-05-04 02:43 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-10 08:14 . 2011-06-10 08:14 -------- d-----w- c:\users\Lada\AppData\Local\Apple Computer
2011-06-10 08:14 . 2011-06-10 08:15 -------- d-----w- c:\users\Lada\AppData\Roaming\Apple Computer
2011-06-10 08:13 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-06-10 08:13 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-06-10 08:12 . 2011-06-10 08:12 -------- d-----w- c:\program files\iPod
2011-06-10 08:12 . 2011-06-10 08:13 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-06-10 08:12 . 2011-06-10 08:13 -------- d-----w- c:\program files\iTunes
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-06-10 08:10 . 2011-06-10 08:10 -------- d-----w- c:\program files\QuickTime
2011-06-10 08:10 . 2011-06-10 08:12 -------- d-----w- c:\programdata\Apple Computer
2011-06-10 08:10 . 2011-06-10 08:10 -------- d-----w- c:\users\Lada\AppData\Local\Apple
2011-06-10 08:10 . 2011-06-10 08:10 -------- d-----w- c:\program files\Apple Software Update
2011-06-10 08:09 . 2011-06-10 08:09 -------- d-----w- c:\program files\Bonjour
2011-06-10 08:09 . 2011-06-10 08:12 -------- d-----w- c:\program files\Common Files\Apple
2011-06-10 08:09 . 2011-06-10 08:09 -------- d-----w- c:\programdata\Apple
2011-06-09 16:05 . 2011-06-09 16:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 18:37 . 2011-06-02 18:37 -------- d-----w- c:\users\Lada\AppData\Local\CrashRpt
2011-06-02 11:54 . 2011-06-02 11:54 -------- d-----w- c:\users\Lada\AppData\Local\The Witcher 2
2011-06-02 10:36 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-06-02 10:36 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-06-02 10:36 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-06-02 10:36 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-06-02 10:36 . 2011-06-02 18:38 -------- d--h--w- c:\windows\msdownld.tmp
2011-05-24 15:05 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-24 17:14 . 2010-10-01 20:31 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-22 18:49 . 2011-05-22 18:49 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-22 18:49 . 2011-05-22 18:49 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-22 18:49 . 2011-05-22 18:49 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-22 18:49 . 2011-05-22 18:49 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-22 18:49 . 2011-05-22 18:49 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-22 18:49 . 2011-05-22 18:49 367104 ----a-w- c:\windows\system32\html.iec
2011-05-22 18:49 . 2011-05-22 18:49 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-22 18:49 . 2011-05-22 18:49 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-22 18:49 . 2011-05-22 18:49 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-22 18:49 . 2011-05-22 18:49 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-22 18:49 . 2011-05-22 18:49 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-22 18:49 . 2011-05-22 18:49 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-22 18:49 . 2011-05-22 18:49 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-22 18:49 . 2011-05-22 18:49 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-22 18:49 . 2011-05-22 18:49 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-22 18:49 . 2011-05-22 18:49 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-22 18:49 . 2011-05-22 18:49 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-22 18:49 . 2011-05-22 18:49 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-22 18:49 . 2011-05-22 18:49 101888 ----a-w- c:\windows\system32\admparse.dll
2011-05-22 18:48 . 2011-05-22 18:48 801792 ----a-w- c:\windows\system32\FntCache.dll
2011-05-22 18:48 . 2011-05-22 18:48 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-05-22 18:48 . 2011-05-22 18:48 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-05-22 18:48 . 2011-05-22 18:48 283648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-05-22 18:48 . 2011-05-22 18:48 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-05-22 18:48 . 2011-05-22 18:48 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-05-22 18:48 . 2011-05-22 18:48 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-05-22 18:48 . 2011-05-22 18:48 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-05-22 18:48 . 2011-05-22 18:48 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2011-05-22 18:48 . 2011-05-22 18:48 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-05-22 18:48 . 2011-05-22 18:48 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2011-05-22 18:48 . 2011-05-22 18:48 107520 ----a-w- c:\windows\system32\cdd.dll
2011-05-22 18:48 . 2011-05-22 18:48 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-05-22 18:48 . 2011-05-22 18:48 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-05-22 18:48 . 2011-05-22 18:48 3181568 ----a-w- c:\windows\system32\mf.dll
2011-05-22 18:48 . 2011-05-22 18:48 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-05-02 10:01 . 2011-05-02 10:01 60416 ----a-w- c:\windows\ALCFDRTM.VER
2011-05-02 10:01 . 2011-05-02 10:01 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2011-04-09 06:13 . 2011-05-11 18:09 3957632 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:13 . 2011-05-11 18:09 3901824 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-08 15:36 . 2011-04-08 15:36 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 14:20 . 2011-04-06 14:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 14:20 . 2011-04-06 14:20 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-06 08:55 . 2011-04-06 08:51 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-04-06 08:55 . 2011-04-06 08:51 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-03-26 14:02 . 2011-03-26 14:02 53723 ----a-w- c:\windows\system32\cmonywbmlrkt.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2011-03-09 247728]
"Creative Live! Cam Manager"="c:\program files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2006-09-06 143360]
"chromium"="c:\users\Lada\AppData\Local\Google\Chrome\Application\chrome.exe" [2011-06-13 1011768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2006-12-26 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2009-06-03 237568]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2009-06-03 131072]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-08-15 24576]
"V0270Mon.exe"="c:\windows\V0270Mon.exe" [2006-09-26 32768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
R2 AutoPower;Auto Power-on;c:\program files\Auto Power-on\AutoPower.exe [2005-07-25 544768]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 PortTalk;PortTalk;c:\windows\system32\Drivers\PortTalk.sys [2002-01-12 3567]
R3 SaiK0836;SaiK0836;c:\windows\system32\DRIVERS\SaiK0836.sys [2008-09-12 107008]
R3 VF0270Dev;Live! Cam Optia;c:\windows\system32\DRIVERS\V0270Dev.sys [2006-10-16 225632]
R3 VF0270Vfx;VF0270 Video FX;c:\windows\system32\DRIVERS\V0270VFx.sys [2006-06-19 6912]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-01 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-02 691696]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422347328-4078365919-150872135-1000Core.job
- c:\users\Lada\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-13 09:03]
.
2011-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422347328-4078365919-150872135-1000UA.job
- c:\users\Lada\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-13 09:03]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: En&queue current page with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebidqueue.htm
IE: Enqueue link target with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebidlinkqueue.htm
IE: Open &link target with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebidlink.htm
IE: Open current page with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebid.htm
IE: Open current page with BID Link Explorer - file://c:\program files\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{E4CA1BA8-67C9-1AC7-213C-5FC6C9BB7144} - (no file)
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-hxglyacyzetywxfct - c:\windows\system32\xnaugydgjnmpbpqa.dll
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2422347328-4078365919-150872135-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2d,a3,a6,7b,cc,dc,5f,26,81,d0,43,d2,9c,4d,1c,bd,86,c5,22,2e,22,ae,30,
0b,19,c8,ec,23,d8,58,42,6a,0f,eb,6f,9f,67,9d,1b,4e,12,1c,f4,33,20,5d,f0,cc,\
"??"=hex:dd,fb,e2,9c,8e,01,c2,67,2f,5f,2b,e3,d4,64,80,f8
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-06-23 11:11:42
ComboFix-quarantined-files.txt 2011-06-23 09:11
.
Před spuštěním: Volných bajtů: 41 300 029 440
Po spuštění: Volných bajtů: 41 176 879 104
.
- - End Of File - - 75994FE5A97518D7D6A456DAF9F0FFD5
tady je log z combofixu:
ComboFix 11-06-22.03 - Lada 23.06.2011 10:50:50.1.1 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2048.903 [GMT 2:00]
Spuštěný z: c:\users\Lada\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-05-23 do 2011-06-23 )))))))))))))))))))))))))))))))
.
.
2011-06-23 09:02 . 2011-06-23 09:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-22 10:57 . 2011-06-20 06:57 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F49F1C9F-B20F-4C77-B173-D5D2F6AE7446}\mpengine.dll
2011-06-19 11:59 . 2011-06-22 11:28 -------- d-----w- C:\8ffc7fd40e86cbff785c20b3ceff0383
2011-06-16 08:11 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-16 08:11 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 08:11 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-16 08:09 . 2010-12-18 05:31 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-16 08:08 . 2011-04-27 02:33 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-16 08:08 . 2011-04-25 04:56 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-16 08:08 . 2011-04-25 02:35 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-16 08:08 . 2011-04-29 02:57 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-16 08:08 . 2011-04-29 02:57 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-16 08:08 . 2011-04-29 02:57 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-16 08:08 . 2011-05-03 04:50 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-16 08:08 . 2011-05-04 02:43 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 08:08 . 2011-05-04 02:43 96256 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 08:08 . 2011-05-04 02:43 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-10 08:14 . 2011-06-10 08:14 -------- d-----w- c:\users\Lada\AppData\Local\Apple Computer
2011-06-10 08:14 . 2011-06-10 08:15 -------- d-----w- c:\users\Lada\AppData\Roaming\Apple Computer
2011-06-10 08:13 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-06-10 08:13 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-06-10 08:12 . 2011-06-10 08:12 -------- d-----w- c:\program files\iPod
2011-06-10 08:12 . 2011-06-10 08:13 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-06-10 08:12 . 2011-06-10 08:13 -------- d-----w- c:\program files\iTunes
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-06-10 08:10 . 2011-06-10 08:10 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-06-10 08:10 . 2011-06-10 08:10 -------- d-----w- c:\program files\QuickTime
2011-06-10 08:10 . 2011-06-10 08:12 -------- d-----w- c:\programdata\Apple Computer
2011-06-10 08:10 . 2011-06-10 08:10 -------- d-----w- c:\users\Lada\AppData\Local\Apple
2011-06-10 08:10 . 2011-06-10 08:10 -------- d-----w- c:\program files\Apple Software Update
2011-06-10 08:09 . 2011-06-10 08:09 -------- d-----w- c:\program files\Bonjour
2011-06-10 08:09 . 2011-06-10 08:12 -------- d-----w- c:\program files\Common Files\Apple
2011-06-10 08:09 . 2011-06-10 08:09 -------- d-----w- c:\programdata\Apple
2011-06-09 16:05 . 2011-06-09 16:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 18:37 . 2011-06-02 18:37 -------- d-----w- c:\users\Lada\AppData\Local\CrashRpt
2011-06-02 11:54 . 2011-06-02 11:54 -------- d-----w- c:\users\Lada\AppData\Local\The Witcher 2
2011-06-02 10:36 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-06-02 10:36 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-06-02 10:36 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-06-02 10:36 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-06-02 10:36 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-06-02 10:36 . 2011-06-02 18:38 -------- d--h--w- c:\windows\msdownld.tmp
2011-05-24 15:05 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-24 17:14 . 2010-10-01 20:31 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-22 18:49 . 2011-05-22 18:49 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-22 18:49 . 2011-05-22 18:49 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-22 18:49 . 2011-05-22 18:49 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-22 18:49 . 2011-05-22 18:49 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-22 18:49 . 2011-05-22 18:49 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-22 18:49 . 2011-05-22 18:49 367104 ----a-w- c:\windows\system32\html.iec
2011-05-22 18:49 . 2011-05-22 18:49 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-22 18:49 . 2011-05-22 18:49 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-22 18:49 . 2011-05-22 18:49 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-22 18:49 . 2011-05-22 18:49 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-22 18:49 . 2011-05-22 18:49 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-22 18:49 . 2011-05-22 18:49 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-22 18:49 . 2011-05-22 18:49 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-22 18:49 . 2011-05-22 18:49 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-22 18:49 . 2011-05-22 18:49 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-22 18:49 . 2011-05-22 18:49 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-22 18:49 . 2011-05-22 18:49 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-22 18:49 . 2011-05-22 18:49 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-22 18:49 . 2011-05-22 18:49 101888 ----a-w- c:\windows\system32\admparse.dll
2011-05-22 18:48 . 2011-05-22 18:48 801792 ----a-w- c:\windows\system32\FntCache.dll
2011-05-22 18:48 . 2011-05-22 18:48 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-05-22 18:48 . 2011-05-22 18:48 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-05-22 18:48 . 2011-05-22 18:48 283648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-05-22 18:48 . 2011-05-22 18:48 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-05-22 18:48 . 2011-05-22 18:48 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-05-22 18:48 . 2011-05-22 18:48 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-05-22 18:48 . 2011-05-22 18:48 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-05-22 18:48 . 2011-05-22 18:48 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2011-05-22 18:48 . 2011-05-22 18:48 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-05-22 18:48 . 2011-05-22 18:48 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2011-05-22 18:48 . 2011-05-22 18:48 107520 ----a-w- c:\windows\system32\cdd.dll
2011-05-22 18:48 . 2011-05-22 18:48 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-05-22 18:48 . 2011-05-22 18:48 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-05-22 18:48 . 2011-05-22 18:48 3181568 ----a-w- c:\windows\system32\mf.dll
2011-05-22 18:48 . 2011-05-22 18:48 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-05-02 10:01 . 2011-05-02 10:01 60416 ----a-w- c:\windows\ALCFDRTM.VER
2011-05-02 10:01 . 2011-05-02 10:01 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2011-04-09 06:13 . 2011-05-11 18:09 3957632 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:13 . 2011-05-11 18:09 3901824 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-08 15:36 . 2011-04-08 15:36 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 14:20 . 2011-04-06 14:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 14:20 . 2011-04-06 14:20 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-06 08:55 . 2011-04-06 08:51 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-04-06 08:55 . 2011-04-06 08:51 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-03-26 14:02 . 2011-03-26 14:02 53723 ----a-w- c:\windows\system32\cmonywbmlrkt.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2011-03-09 247728]
"Creative Live! Cam Manager"="c:\program files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2006-09-06 143360]
"chromium"="c:\users\Lada\AppData\Local\Google\Chrome\Application\chrome.exe" [2011-06-13 1011768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2006-12-26 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2009-06-03 237568]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2009-06-03 131072]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-08-15 24576]
"V0270Mon.exe"="c:\windows\V0270Mon.exe" [2006-09-26 32768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
R2 AutoPower;Auto Power-on;c:\program files\Auto Power-on\AutoPower.exe [2005-07-25 544768]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 PortTalk;PortTalk;c:\windows\system32\Drivers\PortTalk.sys [2002-01-12 3567]
R3 SaiK0836;SaiK0836;c:\windows\system32\DRIVERS\SaiK0836.sys [2008-09-12 107008]
R3 VF0270Dev;Live! Cam Optia;c:\windows\system32\DRIVERS\V0270Dev.sys [2006-10-16 225632]
R3 VF0270Vfx;VF0270 Video FX;c:\windows\system32\DRIVERS\V0270VFx.sys [2006-06-19 6912]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-01 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-02 691696]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422347328-4078365919-150872135-1000Core.job
- c:\users\Lada\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-13 09:03]
.
2011-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422347328-4078365919-150872135-1000UA.job
- c:\users\Lada\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-13 09:03]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: En&queue current page with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebidqueue.htm
IE: Enqueue link target with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebidlinkqueue.htm
IE: Open &link target with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebidlink.htm
IE: Open current page with BID - file://c:\program files\Bulk Image Downloader\iemenu\iebid.htm
IE: Open current page with BID Link Explorer - file://c:\program files\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{E4CA1BA8-67C9-1AC7-213C-5FC6C9BB7144} - (no file)
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-hxglyacyzetywxfct - c:\windows\system32\xnaugydgjnmpbpqa.dll
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2422347328-4078365919-150872135-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2d,a3,a6,7b,cc,dc,5f,26,81,d0,43,d2,9c,4d,1c,bd,86,c5,22,2e,22,ae,30,
0b,19,c8,ec,23,d8,58,42,6a,0f,eb,6f,9f,67,9d,1b,4e,12,1c,f4,33,20,5d,f0,cc,\
"??"=hex:dd,fb,e2,9c,8e,01,c2,67,2f,5f,2b,e3,d4,64,80,f8
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-06-23 11:11:42
ComboFix-quarantined-files.txt 2011-06-23 09:11
.
Před spuštěním: Volných bajtů: 41 300 029 440
Po spuštění: Volných bajtů: 41 176 879 104
.
- - End Of File - - 75994FE5A97518D7D6A456DAF9F0FFD5