vir z Facebooku
Napsal: 19 črc 2011 20:48
Zdravim lidi,
mám také problém s virem skrze chat. V offline režimu bez netu jsem nainstaloval eset s ním projel pc. Všecko co to našlo jsem vymazal nebo vyléčil. Pak jsem použil combofix. Vše se zdálo v pořádku na pc se nerestartoval furt a na FB se šlo bez problémů dostat, jenže furt nešel antivirák. Eset to po připojení k netu bloklo takovou červenou tabulkou. Rozhodl jsem se Eset nainstalovat znova, protože po otevření složky kde měl Eset byt byla prázdná. Jenže před instalací pc spadl a nahodil se nouzový režim a už to nejde vrátit zpět do původního stavu. Pomocí kláves F8 při restartování jsem se dostal na nouzový režim se sítí tak píšu sem. Jinak mě to háže do normálního nouzovyho režimu pořád za všech okolností. Obnova systému skrz ovládací panely nepomáhá. V nouzovym režimu jsem použil již předchozí kombinaci, která zde byla již popsaná s rogue skillem a ještě něčim + combofixem nepomohlo to. Díky za případnou radu nerad bych dával pc do opravny (nejsem zrovna při penězích) a rád bych měl pc s funkčním antivirem a hlavně v normálním režimu ! Hážu sem log z combofixu po provedené operaci po kombinaci s rogue skillem a ještě něčim.
ComboFix 11-07-19.01 - User 19.07.2011 21:08:23.2.4 - x86 NETWORK
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3326.2524 [GMT 2:00]
Spuštěný z: c:\users\User\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-19 do 2011-07-19 )))))))))))))))))))))))))))))))
.
.
2011-07-19 19:14 . 2011-07-19 19:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-19 09:00 . 2011-07-19 09:05 -------- d-----w- c:\users\User\AppData\Local\ElevatedDiagnostics
2011-07-19 08:55 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F8B9211A-D98B-4A0F-B73A-8237AF258344}\mpengine.dll
2011-07-19 08:22 . 2011-07-19 08:22 -------- d-----w- c:\program files\ESET
2011-07-18 20:38 . 2011-07-19 08:48 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-07-18 20:38 . 2011-07-19 06:05 -------- d--h--w- c:\windows\update.tray-3-0
2011-07-18 20:38 . 2011-07-19 06:05 -------- d--h--w- c:\windows\update.tray-2-0
2011-07-18 17:48 . 2011-07-18 17:48 -------- d-----w- c:\users\User\AppData\Local\ESET
2011-07-18 14:30 . 2011-07-18 14:30 0 ----a-w- c:\users\User\AppData\Local\BIT4691.tmp
2011-07-18 11:29 . 2011-07-18 11:29 -------- d-----w- c:\users\User\AppData\Local\AMD
2011-07-18 11:17 . 2011-07-18 11:17 -------- d-----w- c:\programdata\ATI
2011-07-18 11:17 . 2011-07-18 11:17 -------- d-----w- c:\programdata\AMD
2011-07-18 11:16 . 2011-07-18 11:16 -------- d-----w- c:\users\Default\AppData\Roaming\ATI
2011-07-18 11:16 . 2011-07-18 11:16 -------- d-----w- c:\users\Default\AppData\Local\ATI
2011-07-18 10:00 . 2011-07-18 10:00 -------- d-----w- c:\windows\ufa
2011-07-18 09:55 . 2011-07-19 08:48 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-07-18 09:55 . 2011-07-19 06:05 -------- d--h--w- c:\windows\update.tray-14-0
2011-07-17 21:03 . 2011-07-17 21:03 -------- d-----w- c:\users\User\AppData\Roaming\STV Software
2011-07-17 21:02 . 2011-07-19 08:48 -------- d-----w- c:\program files\SensorsViewPro41
2011-07-11 19:08 . 2011-07-19 08:54 -------- d-----w- c:\program files\The Witcher 2
2011-07-09 21:14 . 2011-07-09 21:14 -------- d-----w- c:\users\User\AppData\Local\The Witcher 2
2011-07-09 20:53 . 2011-07-09 20:53 -------- d-----w- c:\program files\Microsoft
2011-07-09 20:53 . 2011-07-09 20:53 -------- d-----w- c:\program files\MSN Toolbar
2011-07-09 20:51 . 2011-07-09 20:54 -------- d-----w- c:\program files\Bing Bar Installer
2011-07-09 20:51 . 2011-07-09 20:51 -------- d--h--w- c:\windows\msdownld.tmp
2011-07-06 06:27 . 2011-07-06 06:27 -------- d-----w- c:\windows\system32\SPReview
2011-07-06 06:25 . 2011-07-06 06:25 -------- d-----w- c:\windows\system32\EventProviders
2011-07-02 11:51 . 2011-07-02 11:51 -------- d-----w- c:\users\User\AppData\Roaming\The Creative Assembly
2011-07-02 11:23 . 2010-03-04 17:22 -------- d-----w- c:\program files\Napoleon Total War
2011-06-29 08:14 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 08:14 . 2010-11-20 12:18 145920 ----a-w- c:\windows\system32\cfgmgr32.dll
2011-06-29 08:14 . 2011-05-04 04:34 1549312 ----a-w- c:\windows\system32\tquery.dll
2011-06-29 08:14 . 2011-05-04 04:32 1401344 ----a-w- c:\windows\system32\mssrch.dll
2011-06-29 08:14 . 2011-05-04 04:28 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 08:14 . 2011-05-04 04:28 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 08:14 . 2011-05-04 04:32 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-29 08:14 . 2011-05-04 04:32 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-29 08:14 . 2011-05-04 04:32 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-29 08:14 . 2011-05-04 04:28 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 08:14 . 2011-05-04 04:32 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-22 13:45 . 2011-06-22 13:45 -------- d-----w- c:\program files\Common Files\Java
2011-06-21 20:42 . 2011-06-21 20:42 -------- d-----w- c:\programdata\CanonIJEPPEX
2011-06-21 12:33 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-06-21 12:33 . 2010-11-20 12:21 11776 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-06-21 12:33 . 2010-11-20 12:19 3215872 ----a-w- c:\windows\system32\mstscax.dll
2011-06-21 12:33 . 2010-11-20 10:24 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2011-06-21 12:33 . 2010-11-20 12:18 1171456 ----a-w- c:\windows\system32\d3d10warp.dll
2011-06-21 12:31 . 2010-11-20 12:20 395264 ----a-w- c:\windows\system32\prnfldr.dll
2011-06-21 12:30 . 2010-11-20 12:21 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-21 12:30 . 2010-11-20 12:21 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-21 12:30 . 2010-11-20 12:21 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-21 12:30 . 2010-11-20 12:19 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-21 12:30 . 2010-11-20 12:21 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-21 12:30 . 2010-11-20 12:21 189952 ----a-w- c:\windows\system32\wdscore.dll
2011-06-21 12:30 . 2010-11-20 12:17 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-21 12:29 . 2010-11-20 12:18 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-06-21 12:29 . 2010-11-20 12:18 257024 ----a-w- c:\windows\system32\dpx.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-11 18:06 . 2010-09-01 11:26 17488 ----a-w- c:\windows\gdrv.sys
2011-07-06 06:40 . 2011-07-06 06:40 203776 ----a-w- c:\windows\system32\webcheck.dll
2011-07-06 06:35 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-09 17:51 . 2011-06-09 17:51 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-09 16:32 . 2011-06-09 16:32 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-06-09 16:32 . 2011-06-09 16:32 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-07 15:55 . 2010-09-03 13:00 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-24 17:13 . 2011-05-24 17:13 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-05-24 17:13 . 2011-05-24 17:13 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-05-04 02:52 . 2011-05-05 13:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-03 04:30 . 2011-06-16 06:04 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46 . 2011-06-16 06:05 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46 . 2011-06-16 06:05 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46 . 2011-06-16 06:05 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17 . 2011-06-16 06:04 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17 . 2011-06-16 06:04 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17 . 2011-06-16 06:04 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31 . 2011-06-16 06:05 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18 . 2011-06-16 06:05 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 19:14 . 2011-05-25 08:36 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-02-10 02:18 . 2010-09-05 09:02 2131336 ----a-w- c:\program files\Common Files\AskToolbarInstaller.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-01 18:17 1487240 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Steam"="c:\program files\Steam\Steam.exe" [2010-11-17 1242448]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2011-01-05 133432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-08 8120864]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-25 98304]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"VC10Player"="c:\program files\Virtual CD v10\System\VC10Play.exe" [2010-04-14 411464]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SaveSnap.lnk - c:\program files\SaveSnap\SaveSnap.exe [2010-12-23 1264128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-03 691696]
R1 MpKsl0856aac9;MpKsl0856aac9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{575638FC-8324-4391-8E40-73DF5F5F78A0}\MpKsl0856aac9.sys [x]
R1 MpKsl08c5a6bd;MpKsl08c5a6bd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2EF5F91E-97E7-42FA-8B16-FC34F6B07D35}\MpKsl08c5a6bd.sys [x]
R1 MpKsl10a3ef9c;MpKsl10a3ef9c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{55A03CCA-8A89-4B70-8559-18DC10564263}\MpKsl10a3ef9c.sys [x]
R1 MpKsl2c0c7dfa;MpKsl2c0c7dfa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EB8C8738-34A6-4B30-9916-EF3788640B3B}\MpKsl2c0c7dfa.sys [x]
R1 MpKsl34a70e3d;MpKsl34a70e3d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{86C17EDA-74E8-415B-8181-5FEA9320DCAB}\MpKsl34a70e3d.sys [x]
R1 MpKsl4c775cd8;MpKsl4c775cd8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7B512DD5-EC72-4846-9862-532F9152B8F0}\MpKsl4c775cd8.sys [x]
R1 MpKsl5089d058;MpKsl5089d058;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C63F2DDC-BE52-49A1-BB43-1D2C93E2F85E}\MpKsl5089d058.sys [x]
R1 MpKsl82e927da;MpKsl82e927da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9B2265C9-72F6-4826-AAD5-3DD204110005}\MpKsl82e927da.sys [x]
R1 MpKsl9996d9fe;MpKsl9996d9fe;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2410AF9-2BB1-4359-8118-342CC0B0EFE7}\MpKsl9996d9fe.sys [x]
R1 MpKsl9fbcda3e;MpKsl9fbcda3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{86C17EDA-74E8-415B-8181-5FEA9320DCAB}\MpKsl9fbcda3e.sys [x]
R1 MpKslb86f1c95;MpKslb86f1c95;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{91E9B4E9-E0EA-4484-A685-F75198F58F8D}\MpKslb86f1c95.sys [x]
R1 MpKslc275244f;MpKslc275244f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D154B264-485F-46B1-BC0A-A0EC850F78D0}\MpKslc275244f.sys [x]
R1 MpKsleb5765d6;MpKsleb5765d6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{05635216-FFB5-434E-9E76-9CEAA4ACAAE5}\MpKsleb5765d6.sys [x]
R1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys [2010-03-25 185880]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-18 136176]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 JMB36X;JMB36X;c:\windows\System32\XSrvSetup.exe [2009-08-06 65536]
R2 VC10SecS;Virtual CD v10 Management Service;c:\program files\Virtual CD v10\System\VC10SecS.exe [2010-04-14 144712]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-11-26 231936]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [2009-09-24 22528]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-18 136176]
R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys [2010-03-10 13952]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [2009-08-26 25480]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-01 1343400]
S0 AFS;AFS; [x]
S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [2009-09-24 19592]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 58880]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 137728]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-01 11:04]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-01 11:04]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1807786179-3034001536-2686373736-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-03 12:59]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1807786179-3034001536-2686373736-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-03 12:59]
.
2011-07-11 c:\windows\Tasks\Norton Security Scan for User.job
- c:\progra~1\NORTON~2\Engine\300~1.103\Nss.exe [2010-12-22 06:36]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.20
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\0ezud4fw.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\vdrv1000]
"ImagePath"="system32\DRIVERS\vdrv1000.sys"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1807786179-3034001536-2686373736-1000\Software\SecuROM\License information*]
"datasecu"=hex:67,d7,a8,5e,eb,93,c6,9b,03,4e,e2,c9,5c,10,55,1f,56,c0,cd,b2,6a,
d8,39,63,c9,91,09,37,64,d1,ac,90,94,e8,b1,fa,02,63,94,d4,8d,b1,8d,38,a0,cd,\
"rkeysecu"=hex:af,b8,22,47,dd,78,40,11,4d,ff,6e,80,5d,fc,2e,56
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-19 21:15:45
ComboFix-quarantined-files.txt 2011-07-19 19:15
ComboFix2.txt 2011-07-19 09:32
ComboFix3.txt 2011-07-19 06:11
.
Před spuštěním: Volných bajtů: 195 511 607 296
Po spuštění: Volných bajtů: 195 417 571 328
.
- - End Of File - - 5AAA823CBD0F096211DA0F1869976814
mám také problém s virem skrze chat. V offline režimu bez netu jsem nainstaloval eset s ním projel pc. Všecko co to našlo jsem vymazal nebo vyléčil. Pak jsem použil combofix. Vše se zdálo v pořádku na pc se nerestartoval furt a na FB se šlo bez problémů dostat, jenže furt nešel antivirák. Eset to po připojení k netu bloklo takovou červenou tabulkou. Rozhodl jsem se Eset nainstalovat znova, protože po otevření složky kde měl Eset byt byla prázdná. Jenže před instalací pc spadl a nahodil se nouzový režim a už to nejde vrátit zpět do původního stavu. Pomocí kláves F8 při restartování jsem se dostal na nouzový režim se sítí tak píšu sem. Jinak mě to háže do normálního nouzovyho režimu pořád za všech okolností. Obnova systému skrz ovládací panely nepomáhá. V nouzovym režimu jsem použil již předchozí kombinaci, která zde byla již popsaná s rogue skillem a ještě něčim + combofixem nepomohlo to. Díky za případnou radu nerad bych dával pc do opravny (nejsem zrovna při penězích) a rád bych měl pc s funkčním antivirem a hlavně v normálním režimu ! Hážu sem log z combofixu po provedené operaci po kombinaci s rogue skillem a ještě něčim.
ComboFix 11-07-19.01 - User 19.07.2011 21:08:23.2.4 - x86 NETWORK
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3326.2524 [GMT 2:00]
Spuštěný z: c:\users\User\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-19 do 2011-07-19 )))))))))))))))))))))))))))))))
.
.
2011-07-19 19:14 . 2011-07-19 19:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-19 09:00 . 2011-07-19 09:05 -------- d-----w- c:\users\User\AppData\Local\ElevatedDiagnostics
2011-07-19 08:55 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F8B9211A-D98B-4A0F-B73A-8237AF258344}\mpengine.dll
2011-07-19 08:22 . 2011-07-19 08:22 -------- d-----w- c:\program files\ESET
2011-07-18 20:38 . 2011-07-19 08:48 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-07-18 20:38 . 2011-07-19 06:05 -------- d--h--w- c:\windows\update.tray-3-0
2011-07-18 20:38 . 2011-07-19 06:05 -------- d--h--w- c:\windows\update.tray-2-0
2011-07-18 17:48 . 2011-07-18 17:48 -------- d-----w- c:\users\User\AppData\Local\ESET
2011-07-18 14:30 . 2011-07-18 14:30 0 ----a-w- c:\users\User\AppData\Local\BIT4691.tmp
2011-07-18 11:29 . 2011-07-18 11:29 -------- d-----w- c:\users\User\AppData\Local\AMD
2011-07-18 11:17 . 2011-07-18 11:17 -------- d-----w- c:\programdata\ATI
2011-07-18 11:17 . 2011-07-18 11:17 -------- d-----w- c:\programdata\AMD
2011-07-18 11:16 . 2011-07-18 11:16 -------- d-----w- c:\users\Default\AppData\Roaming\ATI
2011-07-18 11:16 . 2011-07-18 11:16 -------- d-----w- c:\users\Default\AppData\Local\ATI
2011-07-18 10:00 . 2011-07-18 10:00 -------- d-----w- c:\windows\ufa
2011-07-18 09:55 . 2011-07-19 08:48 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-07-18 09:55 . 2011-07-19 06:05 -------- d--h--w- c:\windows\update.tray-14-0
2011-07-17 21:03 . 2011-07-17 21:03 -------- d-----w- c:\users\User\AppData\Roaming\STV Software
2011-07-17 21:02 . 2011-07-19 08:48 -------- d-----w- c:\program files\SensorsViewPro41
2011-07-11 19:08 . 2011-07-19 08:54 -------- d-----w- c:\program files\The Witcher 2
2011-07-09 21:14 . 2011-07-09 21:14 -------- d-----w- c:\users\User\AppData\Local\The Witcher 2
2011-07-09 20:53 . 2011-07-09 20:53 -------- d-----w- c:\program files\Microsoft
2011-07-09 20:53 . 2011-07-09 20:53 -------- d-----w- c:\program files\MSN Toolbar
2011-07-09 20:51 . 2011-07-09 20:54 -------- d-----w- c:\program files\Bing Bar Installer
2011-07-09 20:51 . 2011-07-09 20:51 -------- d--h--w- c:\windows\msdownld.tmp
2011-07-06 06:27 . 2011-07-06 06:27 -------- d-----w- c:\windows\system32\SPReview
2011-07-06 06:25 . 2011-07-06 06:25 -------- d-----w- c:\windows\system32\EventProviders
2011-07-02 11:51 . 2011-07-02 11:51 -------- d-----w- c:\users\User\AppData\Roaming\The Creative Assembly
2011-07-02 11:23 . 2010-03-04 17:22 -------- d-----w- c:\program files\Napoleon Total War
2011-06-29 08:14 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 08:14 . 2010-11-20 12:18 145920 ----a-w- c:\windows\system32\cfgmgr32.dll
2011-06-29 08:14 . 2011-05-04 04:34 1549312 ----a-w- c:\windows\system32\tquery.dll
2011-06-29 08:14 . 2011-05-04 04:32 1401344 ----a-w- c:\windows\system32\mssrch.dll
2011-06-29 08:14 . 2011-05-04 04:28 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 08:14 . 2011-05-04 04:28 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 08:14 . 2011-05-04 04:32 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-29 08:14 . 2011-05-04 04:32 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-29 08:14 . 2011-05-04 04:32 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-29 08:14 . 2011-05-04 04:28 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 08:14 . 2011-05-04 04:32 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-22 13:45 . 2011-06-22 13:45 -------- d-----w- c:\program files\Common Files\Java
2011-06-21 20:42 . 2011-06-21 20:42 -------- d-----w- c:\programdata\CanonIJEPPEX
2011-06-21 12:33 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-06-21 12:33 . 2010-11-20 12:21 11776 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-06-21 12:33 . 2010-11-20 12:19 3215872 ----a-w- c:\windows\system32\mstscax.dll
2011-06-21 12:33 . 2010-11-20 10:24 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2011-06-21 12:33 . 2010-11-20 12:18 1171456 ----a-w- c:\windows\system32\d3d10warp.dll
2011-06-21 12:31 . 2010-11-20 12:20 395264 ----a-w- c:\windows\system32\prnfldr.dll
2011-06-21 12:30 . 2010-11-20 12:21 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-21 12:30 . 2010-11-20 12:21 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-21 12:30 . 2010-11-20 12:21 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-21 12:30 . 2010-11-20 12:19 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-21 12:30 . 2010-11-20 12:21 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-21 12:30 . 2010-11-20 12:21 189952 ----a-w- c:\windows\system32\wdscore.dll
2011-06-21 12:30 . 2010-11-20 12:17 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-21 12:29 . 2010-11-20 12:18 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-06-21 12:29 . 2010-11-20 12:18 257024 ----a-w- c:\windows\system32\dpx.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-11 18:06 . 2010-09-01 11:26 17488 ----a-w- c:\windows\gdrv.sys
2011-07-06 06:40 . 2011-07-06 06:40 203776 ----a-w- c:\windows\system32\webcheck.dll
2011-07-06 06:35 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-09 17:51 . 2011-06-09 17:51 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-09 16:32 . 2011-06-09 16:32 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-06-09 16:32 . 2011-06-09 16:32 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-07 15:55 . 2010-09-03 13:00 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-24 17:13 . 2011-05-24 17:13 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-05-24 17:13 . 2011-05-24 17:13 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-05-04 02:52 . 2011-05-05 13:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-03 04:30 . 2011-06-16 06:04 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46 . 2011-06-16 06:05 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46 . 2011-06-16 06:05 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46 . 2011-06-16 06:05 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17 . 2011-06-16 06:04 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17 . 2011-06-16 06:04 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17 . 2011-06-16 06:04 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31 . 2011-06-16 06:05 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18 . 2011-06-16 06:05 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 19:14 . 2011-05-25 08:36 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-02-10 02:18 . 2010-09-05 09:02 2131336 ----a-w- c:\program files\Common Files\AskToolbarInstaller.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-01 18:17 1487240 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Steam"="c:\program files\Steam\Steam.exe" [2010-11-17 1242448]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2011-01-05 133432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-08 8120864]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-25 98304]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"VC10Player"="c:\program files\Virtual CD v10\System\VC10Play.exe" [2010-04-14 411464]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SaveSnap.lnk - c:\program files\SaveSnap\SaveSnap.exe [2010-12-23 1264128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-03 691696]
R1 MpKsl0856aac9;MpKsl0856aac9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{575638FC-8324-4391-8E40-73DF5F5F78A0}\MpKsl0856aac9.sys [x]
R1 MpKsl08c5a6bd;MpKsl08c5a6bd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2EF5F91E-97E7-42FA-8B16-FC34F6B07D35}\MpKsl08c5a6bd.sys [x]
R1 MpKsl10a3ef9c;MpKsl10a3ef9c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{55A03CCA-8A89-4B70-8559-18DC10564263}\MpKsl10a3ef9c.sys [x]
R1 MpKsl2c0c7dfa;MpKsl2c0c7dfa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EB8C8738-34A6-4B30-9916-EF3788640B3B}\MpKsl2c0c7dfa.sys [x]
R1 MpKsl34a70e3d;MpKsl34a70e3d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{86C17EDA-74E8-415B-8181-5FEA9320DCAB}\MpKsl34a70e3d.sys [x]
R1 MpKsl4c775cd8;MpKsl4c775cd8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7B512DD5-EC72-4846-9862-532F9152B8F0}\MpKsl4c775cd8.sys [x]
R1 MpKsl5089d058;MpKsl5089d058;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C63F2DDC-BE52-49A1-BB43-1D2C93E2F85E}\MpKsl5089d058.sys [x]
R1 MpKsl82e927da;MpKsl82e927da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9B2265C9-72F6-4826-AAD5-3DD204110005}\MpKsl82e927da.sys [x]
R1 MpKsl9996d9fe;MpKsl9996d9fe;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2410AF9-2BB1-4359-8118-342CC0B0EFE7}\MpKsl9996d9fe.sys [x]
R1 MpKsl9fbcda3e;MpKsl9fbcda3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{86C17EDA-74E8-415B-8181-5FEA9320DCAB}\MpKsl9fbcda3e.sys [x]
R1 MpKslb86f1c95;MpKslb86f1c95;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{91E9B4E9-E0EA-4484-A685-F75198F58F8D}\MpKslb86f1c95.sys [x]
R1 MpKslc275244f;MpKslc275244f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D154B264-485F-46B1-BC0A-A0EC850F78D0}\MpKslc275244f.sys [x]
R1 MpKsleb5765d6;MpKsleb5765d6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{05635216-FFB5-434E-9E76-9CEAA4ACAAE5}\MpKsleb5765d6.sys [x]
R1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys [2010-03-25 185880]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-18 136176]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 JMB36X;JMB36X;c:\windows\System32\XSrvSetup.exe [2009-08-06 65536]
R2 VC10SecS;Virtual CD v10 Management Service;c:\program files\Virtual CD v10\System\VC10SecS.exe [2010-04-14 144712]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-11-26 231936]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [2009-09-24 22528]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-18 136176]
R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys [2010-03-10 13952]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [2009-08-26 25480]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-01 1343400]
S0 AFS;AFS; [x]
S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [2009-09-24 19592]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 58880]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 137728]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-01 11:04]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-01 11:04]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1807786179-3034001536-2686373736-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-03 12:59]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1807786179-3034001536-2686373736-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-03 12:59]
.
2011-07-11 c:\windows\Tasks\Norton Security Scan for User.job
- c:\progra~1\NORTON~2\Engine\300~1.103\Nss.exe [2010-12-22 06:36]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.20
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\0ezud4fw.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\vdrv1000]
"ImagePath"="system32\DRIVERS\vdrv1000.sys"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1807786179-3034001536-2686373736-1000\Software\SecuROM\License information*]
"datasecu"=hex:67,d7,a8,5e,eb,93,c6,9b,03,4e,e2,c9,5c,10,55,1f,56,c0,cd,b2,6a,
d8,39,63,c9,91,09,37,64,d1,ac,90,94,e8,b1,fa,02,63,94,d4,8d,b1,8d,38,a0,cd,\
"rkeysecu"=hex:af,b8,22,47,dd,78,40,11,4d,ff,6e,80,5d,fc,2e,56
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-19 21:15:45
ComboFix-quarantined-files.txt 2011-07-19 19:15
ComboFix2.txt 2011-07-19 09:32
ComboFix3.txt 2011-07-19 06:11
.
Před spuštěním: Volných bajtů: 195 511 607 296
Po spuštění: Volných bajtů: 195 417 571 328
.
- - End Of File - - 5AAA823CBD0F096211DA0F1869976814