Combofix
Napsal: 24 srp 2011 13:12
Zdravím,
zdálo se mi, že počítač je najednou pomalejší než dříve, tak jsem zkusil combo fix. Avšak se nevyznám ve výpisu, který mi poskytl, tak vás prosím o radu, zda v počítači nějaké viry mám, pokud ano, tak co mám udělat pro jejich odstranění a také jestli nějaké viry smazal. Předem všem děkuji za pomoc. Zde přikládám výpis:
ComboFix 11-08-24.02 - Ondřej 24.08.2011 13:06:27.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3067.2326 [GMT 2:00]
Spuštěný z: c:\users\Ondřej\Downloads\ComboFix.exe
AV: Emsisoft Anti-Malware *Disabled/Updated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A}
SP: Emsisoft Anti-Malware *Disabled/Updated* {B1BD7E99-06FB-2B81-3B52-7834153DC387}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-24 do 2011-08-24 )))))))))))))))))))))))))))))))
.
.
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Tomáš\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Tomáš.Ondřej-PC\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-24 10:53 . 2011-08-24 10:53 301568 ----a-w- c:\windows\system32\cmd.execf
2011-08-22 21:33 . 2011-08-22 21:33 -------- d-----w- c:\program files\ESET
2011-08-22 20:47 . 2011-08-24 10:34 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-08-22 20:47 . 2011-08-24 10:34 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-08-22 18:16 . 2011-08-23 10:30 -------- d-----w- c:\users\Ondřej\AppData\Local\CrashDumps
2011-08-22 08:24 . 2011-08-24 10:34 -------- d-----w- c:\programdata\Norton
2011-08-21 11:58 . 2011-08-21 11:58 -------- d-----w- c:\users\Ondřej\AppData\Roaming\Rovio
2011-08-21 10:38 . 2011-08-21 10:38 -------- d-----w- c:\users\Guest\GTA San Andreas
2011-08-13 08:44 . 2011-08-24 11:01 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-07-31 15:07 . 2011-07-31 15:07 -------- d-----w- c:\program files\Rockstar Games
2011-07-31 15:07 . 2004-10-22 00:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2011-07-31 15:07 . 2004-10-22 00:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2011-07-31 15:07 . 2004-10-22 00:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2011-07-31 15:07 . 2004-10-22 00:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2011-07-31 15:07 . 2004-10-22 00:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2011-07-31 15:07 . 2011-07-31 15:07 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2011-07-31 15:07 . 2011-07-31 15:07 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-11 18:40 . 2011-07-10 08:38 40904 ----a-w- c:\windows\system32\drivers\gdwfpcd32.sys
2011-07-11 18:32 . 2011-07-11 18:32 29992 ----a-w- c:\windows\system32\drivers\GRD.sys
2011-07-11 18:29 . 2011-06-04 18:13 61512 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2011-07-11 18:29 . 2011-07-10 08:38 33480 ----a-w- c:\windows\system32\drivers\GDBehave.sys
2011-07-04 07:20 . 2011-07-04 07:20 48344 ----a-w- c:\windows\system32\drivers\PktIcpt.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-03-07 200704]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"a-squared"="c:\program files\EMSISOFT ANTI-MALWARE\a2guard.exe" [2011-06-23 3321232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
2010-03-06 16:46 286720 ----a-w- c:\program files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
2011-07-18 13:26 6812032 ----a-w- c:\program files\QIP 2010\qip.exe
.
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 135664]
R3 GDPkIcpt;GDPkIcpt;c:\windows\system32\drivers\PktIcpt.sys [2011-07-04 48344]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 135664]
R3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys [2010-12-15 94336]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-15 691696]
S1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [2010-09-05 41928]
S1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-20 73728]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 18:09]
.
2011-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 18:09]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyServer = linda.guh.cz:3128
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\iqebxpp5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Searchrise
FF - prefs.js: browser.startup.homepage - hxxp://searchrise.com?hl=cs&fh=
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: Trendster Toolbar: {699661f3-1e3b-4129-831b-cd5660cdc72e} - %profile%\extensions\{699661f3-1e3b-4129-831b-cd5660cdc72e}
FF - Ext: Safe Browse: {8445d605-e889-9c78-e3f4-c579193cb55f} - %profile%\extensions\{8445d605-e889-9c78-e3f4-c579193cb55f}
FF - Ext: QipAuthorizer: {32a1fd71-835e-4b11-8e54-886fda0b4c89} - %profile%\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-QIP Internet Guardian - c:\users\Ondřej\AppData\Roaming\QipGuard\QipGuard.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1334649269-3934671240-21666210-1000\Software\SecuROM\License information*]
"datasecu"=hex:ca,8a,10,32,91,b1,5a,8e,33,b4,0b,2a,e0,e9,b2,b4,96,f5,c6,a7,d6,
7e,e4,ce,1f,5b,da,15,c6,89,31,cc,42,b1,31,ff,d1,64,1a,a4,6b,86,d2,e8,20,e6,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3464)
c:\windows\system32\wlanutil.dll
.
Celkový čas: 2011-08-24 13:22:17
ComboFix-quarantined-files.txt 2011-08-24 11:22
ComboFix2.txt 2011-07-11 20:05
.
Před spuštěním: Volných bajtů: 312 179 937 280
Po spuštění: Volných bajtů: 312 168 513 536
.
- - End Of File - - 10E788C4007B978C80DCCEF1A3EA7426
zdálo se mi, že počítač je najednou pomalejší než dříve, tak jsem zkusil combo fix. Avšak se nevyznám ve výpisu, který mi poskytl, tak vás prosím o radu, zda v počítači nějaké viry mám, pokud ano, tak co mám udělat pro jejich odstranění a také jestli nějaké viry smazal. Předem všem děkuji za pomoc. Zde přikládám výpis:
ComboFix 11-08-24.02 - Ondřej 24.08.2011 13:06:27.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3067.2326 [GMT 2:00]
Spuštěný z: c:\users\Ondřej\Downloads\ComboFix.exe
AV: Emsisoft Anti-Malware *Disabled/Updated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A}
SP: Emsisoft Anti-Malware *Disabled/Updated* {B1BD7E99-06FB-2B81-3B52-7834153DC387}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-24 do 2011-08-24 )))))))))))))))))))))))))))))))
.
.
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Tomáš\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Tomáš.Ondřej-PC\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-08-24 11:14 . 2011-08-24 11:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-24 10:53 . 2011-08-24 10:53 301568 ----a-w- c:\windows\system32\cmd.execf
2011-08-22 21:33 . 2011-08-22 21:33 -------- d-----w- c:\program files\ESET
2011-08-22 20:47 . 2011-08-24 10:34 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-08-22 20:47 . 2011-08-24 10:34 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-08-22 18:16 . 2011-08-23 10:30 -------- d-----w- c:\users\Ondřej\AppData\Local\CrashDumps
2011-08-22 08:24 . 2011-08-24 10:34 -------- d-----w- c:\programdata\Norton
2011-08-21 11:58 . 2011-08-21 11:58 -------- d-----w- c:\users\Ondřej\AppData\Roaming\Rovio
2011-08-21 10:38 . 2011-08-21 10:38 -------- d-----w- c:\users\Guest\GTA San Andreas
2011-08-13 08:44 . 2011-08-24 11:01 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-07-31 15:07 . 2011-07-31 15:07 -------- d-----w- c:\program files\Rockstar Games
2011-07-31 15:07 . 2004-10-22 00:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2011-07-31 15:07 . 2004-10-22 00:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2011-07-31 15:07 . 2004-10-22 00:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2011-07-31 15:07 . 2004-10-22 00:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2011-07-31 15:07 . 2004-10-22 00:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2011-07-31 15:07 . 2011-07-31 15:07 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2011-07-31 15:07 . 2011-07-31 15:07 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-11 18:40 . 2011-07-10 08:38 40904 ----a-w- c:\windows\system32\drivers\gdwfpcd32.sys
2011-07-11 18:32 . 2011-07-11 18:32 29992 ----a-w- c:\windows\system32\drivers\GRD.sys
2011-07-11 18:29 . 2011-06-04 18:13 61512 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2011-07-11 18:29 . 2011-07-10 08:38 33480 ----a-w- c:\windows\system32\drivers\GDBehave.sys
2011-07-04 07:20 . 2011-07-04 07:20 48344 ----a-w- c:\windows\system32\drivers\PktIcpt.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-03-07 200704]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"a-squared"="c:\program files\EMSISOFT ANTI-MALWARE\a2guard.exe" [2011-06-23 3321232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
2010-03-06 16:46 286720 ----a-w- c:\program files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
2011-07-18 13:26 6812032 ----a-w- c:\program files\QIP 2010\qip.exe
.
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 135664]
R3 GDPkIcpt;GDPkIcpt;c:\windows\system32\drivers\PktIcpt.sys [2011-07-04 48344]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 135664]
R3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys [2010-12-15 94336]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-15 691696]
S1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [2010-09-05 41928]
S1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-20 73728]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 18:09]
.
2011-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-24 18:09]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyServer = linda.guh.cz:3128
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\iqebxpp5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Searchrise
FF - prefs.js: browser.startup.homepage - hxxp://searchrise.com?hl=cs&fh=
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: Trendster Toolbar: {699661f3-1e3b-4129-831b-cd5660cdc72e} - %profile%\extensions\{699661f3-1e3b-4129-831b-cd5660cdc72e}
FF - Ext: Safe Browse: {8445d605-e889-9c78-e3f4-c579193cb55f} - %profile%\extensions\{8445d605-e889-9c78-e3f4-c579193cb55f}
FF - Ext: QipAuthorizer: {32a1fd71-835e-4b11-8e54-886fda0b4c89} - %profile%\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-QIP Internet Guardian - c:\users\Ondřej\AppData\Roaming\QipGuard\QipGuard.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1334649269-3934671240-21666210-1000\Software\SecuROM\License information*]
"datasecu"=hex:ca,8a,10,32,91,b1,5a,8e,33,b4,0b,2a,e0,e9,b2,b4,96,f5,c6,a7,d6,
7e,e4,ce,1f,5b,da,15,c6,89,31,cc,42,b1,31,ff,d1,64,1a,a4,6b,86,d2,e8,20,e6,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3464)
c:\windows\system32\wlanutil.dll
.
Celkový čas: 2011-08-24 13:22:17
ComboFix-quarantined-files.txt 2011-08-24 11:22
ComboFix2.txt 2011-07-11 20:05
.
Před spuštěním: Volných bajtů: 312 179 937 280
Po spuštění: Volných bajtů: 312 168 513 536
.
- - End Of File - - 10E788C4007B978C80DCCEF1A3EA7426