Prosim o kontrolu Logu z Combofixu
Napsal: 19 pro 2011 10:34
zdravim. Pocitac mi posledni dobou zamrza atd... Proto jsem udelal log v combofixu pro kontrolu... Dekuji za pomoc
ComboFix 11-12-19.01 - GTR 19.12.2011 10:15:47.3.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.8126.5349 [GMT 1:00]
Spuštěný z: C:\Users\GTR\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
C:\windows\security\Database\tmp.edb
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-19 do 2011-12-19 )))))))))))))))))))))))))))))))
2011-12-19 09:21:02 . 2011-12-19 09:21:02 -------- d-----w- C:\Users\Default\AppData\Local\temp
2011-12-16 13:36:52 . 2011-12-16 13:36:52 -------- d-----w- C:\Users\GTR\AppData\Local\PowerDVDCox
2011-12-16 13:36:51 . 2011-12-16 13:36:51 -------- d-----w- C:\Users\GTR\AppData\Local\PowerDVDCinema
2011-12-16 13:32:51 . 2011-12-16 13:32:51 -------- d-----w- C:\Program Files (x86)\Common Files\CyberLink
2011-12-16 13:32:44 . 2011-12-16 13:33:53 505128 ----a-w- C:\windows\SysWow64\msvcp71.dll
2011-12-16 13:32:44 . 2011-12-16 13:33:53 353576 ----a-w- C:\windows\SysWow64\msvcr71.dll
2011-12-16 12:15:54 . 2011-12-16 12:15:54 -------- d-----w- C:\Users\GTR\AppData\Local\Apps
2011-12-16 12:15:53 . 2011-12-16 20:39:14 -------- d-----w- C:\Users\GTR\AppData\Local\Deployment
2011-12-15 10:17:00 . 2011-12-15 12:13:54 -------- d-----w- C:\wamp
2011-12-15 10:12:43 . 2011-12-15 10:12:43 -------- d-----w- C:\Users\GTR\AppData\Local\Windows Live
2011-12-15 02:34:39 . 2011-12-15 02:34:39 0 ----a-w- C:\windows\SysWow64\sho8A4D.tmp
2011-12-14 20:43:00 . 2011-11-05 05:32:50 2048 ----a-w- C:\windows\system32\tzres.dll
2011-12-14 20:43:00 . 2011-11-05 04:26:03 2048 ----a-w- C:\windows\SysWow64\tzres.dll
2011-12-14 20:41:58 . 2011-11-05 03:32:47 1638912 ----a-w- C:\windows\system32\mshtml.tlb
2011-12-14 20:41:58 . 2011-11-05 02:48:51 1638912 ----a-w- C:\windows\SysWow64\mshtml.tlb
2011-12-14 20:41:46 . 2011-11-24 04:52:09 3145216 ----a-w- C:\windows\system32\win32k.sys
2011-12-14 20:41:41 . 2011-10-15 06:31:56 723456 ----a-w- C:\windows\system32\EncDec.dll
2011-12-14 20:41:41 . 2011-10-15 05:38:59 534528 ----a-w- C:\windows\SysWow64\EncDec.dll
2011-12-12 11:06:45 . 2011-12-16 21:25:36 -------- d-----w- C:\Users\GTR\AppData\Roaming\FileZilla
2011-12-12 11:06:27 . 2011-12-12 11:06:36 -------- d-----w- C:\Program Files (x86)\FileZilla FTP Client
2011-12-11 10:53:21 . 2011-12-11 10:53:21 -------- d-----w- C:\windows\Sun
2011-12-11 10:52:55 . 2011-12-11 10:52:55 -------- d-----w- C:\Program Files (x86)\Common Files\Java
2011-12-11 10:52:30 . 2011-12-11 10:51:54 472808 ----a-w- C:\windows\SysWow64\deployJava1.dll
2011-12-11 10:51:49 . 2011-12-11 10:51:49 -------- d-----w- C:\Program Files (x86)\Java
2011-12-07 19:15:59 . 2011-12-07 19:15:59 -------- d-----w- C:\Users\GTR\AppData\Roaming\PlatinumHideIP
2011-12-07 19:15:59 . 2011-12-07 19:15:59 -------- d-----w- C:\ProgramData\PlatinumHideIP
2011-12-07 19:15:14 . 2011-12-07 19:15:18 -------- d-----w- C:\Program Files (x86)\PlatinumHideIP
2011-12-07 19:04:35 . 2011-12-07 19:04:35 -------- d-----w- C:\Users\GTR\AppData\Roaming\FreeHideIP
2011-12-07 19:04:35 . 2011-12-07 19:04:35 -------- d-----w- C:\ProgramData\FreeHideIP
2011-11-30 07:54:04 . 2006-01-17 20:00:18 14008 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\DOM.JS
2011-11-30 07:54:04 . 2006-01-17 20:00:14 14643 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\FPLIB.JS
2011-11-30 07:54:04 . 2006-01-17 20:00:10 12235 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\GETOBJ.JS
2011-11-30 07:54:04 . 2006-01-17 19:58:24 18866 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\PRELOAD.JS
2011-11-30 07:54:04 . 2006-01-17 19:58:20 18466 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\SETTEXT.JS
2011-11-30 07:54:04 . 2006-01-17 19:57:28 22188 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\STRINGS.JS
2011-11-30 07:54:04 . 2006-01-17 19:56:54 11964 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\_JMPMENU.JS
2011-11-30 07:54:04 . 2006-01-17 19:56:48 15579 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\_PRELOAD.JS
2011-11-20 23:45:39 . 2011-12-18 21:42:04 -------- d-----w- C:\Users\GTR\AppData\Roaming\HLSW
2011-11-20 23:45:39 . 2011-11-20 23:45:46 -------- d-s---w- C:\Program Files (x86)\HLSW
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-12-18 19:51:41 . 2011-10-26 08:06:52 214520 ----a-w- C:\windows\SysWow64\PnkBstrB.xtr
2011-12-18 19:51:41 . 2011-10-25 11:36:18 214520 ----a-w- C:\windows\SysWow64\PnkBstrB.exe
2011-12-18 19:49:16 . 2011-10-25 11:36:18 214520 ----a-w- C:\windows\SysWow64\PnkBstrB.ex0
2011-11-18 01:11:03 . 2011-11-18 01:11:03 0 ----a-w- C:\windows\SysWow64\sho57FB.tmp
2011-11-17 19:02:03 . 2011-10-25 11:36:16 75136 ----a-w- C:\windows\SysWow64\PnkBstrA.exe
2011-11-01 18:08:44 . 2011-11-01 18:08:44 2434856 ----a-w- C:\windows\SysWow64\pbsvc_bc2.exe
2011-10-25 11:53:12 . 2011-10-25 11:53:12 21832 ----a-w- C:\windows\system32\drivers\hamachi.sys
2011-10-25 11:36:15 . 2011-10-25 11:36:15 682280 ----a-w- C:\windows\SysWow64\pbsvc.exe
2011-10-23 11:53:14 . 2009-07-14 02:36:51 175616 ----a-w- C:\windows\system32\msclmd.dll
2011-10-23 11:53:14 . 2009-07-14 02:36:51 152576 ----a-w- C:\windows\SysWow64\msclmd.dll
2011-10-22 23:17:39 . 2011-10-22 23:17:39 0 ----a-w- C:\windows\SysWow64\shoA636.tmp
2011-09-30 15:28:10 . 2011-09-30 15:28:10 0 ----a-w- C:\windows\SysWow64\sho45BD.tmp
2011-09-29 16:29:28 . 2011-11-09 08:04:42 1923952 ----a-w- C:\windows\system32\drivers\tcpip.sys
2011-09-27 02:39:24 . 2011-10-25 11:58:41 286208 ----a-w- C:\windows\SysWow64\binkw32.dll
2011-09-26 06:15:46 . 2011-09-26 06:15:46 0 ----a-w- C:\windows\SysWow64\sho8279.tmp
2011-09-25 07:23:33 . 2011-09-25 07:23:33 178800 ----a-w- C:\windows\SysWow64\CmdLineExt_x64.dll
2011-09-24 18:18:25 . 2011-09-16 12:38:58 404640 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-24 18:06:49 . 2011-09-24 18:07:07 368912 ----a-w- C:\windows\SysWow64\VBAR332.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 252176 ----a-w- C:\windows\SysWow64\MSRD2X35.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 24848 ----a-w- C:\windows\SysWow64\MSJTER35.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 123664 ----a-w- C:\windows\SysWow64\MSJINT35.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 1045776 ----a-w- C:\windows\SysWow64\MSJET35.DLL
2011-09-23 09:14:53 . 2011-09-23 09:15:00 627600 ----a-w- C:\windows\system32\deployJava1.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-06-20 13:07:06 2736128]
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 07:33:30 4910912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"PDF Complete"="C:\Program Files (x86)\PDF Complete\pdfsty.exe" [2011-02-01 08:23:10 656920]
"Microsoft Default Manager"="C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 21:12:28 439568]
"QLBController"="C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-01-28 22:24:56 299576]
"File Sanitizer"="C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2011-02-07 18:41:42 12274688]
"IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-26 17:00:32 283160]
"NUSB3MON"="c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 17:53:16 113288]
"HP HD Webcam [Fixed]_Monitor"="C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe" [2010-11-26 11:31:18 267128]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-28 18:38:48 336384]
"DTRun"="c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe" [2010-11-24 18:00:06 517456]
"HPConnectionManager"="c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-04-05 18:13:58 94264]
"HPQuickWebProxy"="c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-02-11 00:44:28 76344]
"LogMeIn Hamachi Ui"="C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 14:18:14 1955208]
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 09:44:34 31072]
"NBAgent"="C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 12:53:16 1493288]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 12:06:06 254696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
GamePark klient 2.lnk - C:\Program Files\GamePark2\gpcl.exe [2011-10-25 442880]
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2011-02-03 22:09:12 75360 ----a-w- C:\Windows\System32\DeviceNP.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~2\SEARCH~1\SEARCH~1\datamngr.dll C:\PROGRA~2\SEARCH~1\SEARCH~1\IEBHO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 20:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 21:27:14 138576]
R2 XobniService;XobniService;C:\Program Files (x86)\Xobni\XobniService.exe [2011-03-07 20:48:10 62184]
R3 DAMDrv;DAMDrv;C:\windows\system32\DRIVERS\DAMDrv64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\Windows\SysWOW64\flcdlock.exe [2011-02-03 22:09:18 464480]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 18:13:46 1094712]
R3 JMCR;JMCR;C:\windows\system32\DRIVERS\jmcr.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 12:49:20 227232]
R3 nmwcdcx64;Nokia USB Generic;C:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;C:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 19:34:24 4925184]
R3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;C:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 dlkmdldr;dlkmdldr;C:\windows\system32\drivers\dlkmdldr.sys [x]
S0 MfeEpePc;MfeEpePc; [x]
S0 NBVol;Nero Backup Volume Filter Driver;C:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;C:\windows\system32\DRIVERS\NBVolUp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;C:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 10:42:00 89600]
S2 AMD External Events Utility;AMD External Events Utility;C:\windows\system32\atiesrxx.exe [x]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 03:08:38 138400]
S2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 03:06:56 53920]
S2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 13:23:26 821664]
S2 DisplayLinkService;DisplayLinkManager;C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2009-11-20 01:47:50 8547176]
S2 eamonm;eamonm;C:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 10:03:30 974944]
S2 epfwwfpr;epfwwfpr;C:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 FAH-01;Folding Service 01;C:\Program Files (x86)\Folding@Home 01\Folding@Home 01\FAH-Console.exe [2008-06-30 19:38:32 253952]
S2 FAH-02;Folding Service 02;C:\Program Files (x86)\Folding@Home 01\Folding@Home 02\FAH-Console.exe [2008-06-30 19:38:32 253952]
S2 GS In-Game Service;GS In-Game Service;C:\Program Files (x86)\GameTracker\GSInGameService.exe [2011-10-25 20:13:02 1677096]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 14:18:12 2329480]
S2 HP Power Assistant Service;HP Power Assistant Service;C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 01:11:48 131128]
S2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 13:57:34 85560]
S2 HPDayStarterService;HP DayStarter Service;c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 16:41:30 133688]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 00:07:50 94264]
S2 HPFSService;File Sanitizer for HP ProtectTools;C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 18:41:26 320000]
S2 hpHotkeyMonitor;hpHotkeyMonitor;C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-28 22:27:06 281656]
S2 hpsrv;HP Service;C:\windows\system32\Hpservice.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 17:00:00 13336]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 19:10:32 210896]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 18:28:12 1318912]
S2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-09-23 16:37:42 641832]
S2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 08:23:10 1127448]
S2 PdiService;Portrait Displays SDK Service;C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 20:42:44 113264]
S2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 03:45:44 508264]
S2 uArcCapture;ArcCapture;C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 07:43:00 502464]
S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 19:42:04 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service;C:\windows\system32\vcsFPService.exe [2011-01-22 02:36:02 3154224]
S3 amdkmdag;amdkmdag;C:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;C:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;C:\windows\system32\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\windows\system32\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;C:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\windows\system32\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\windows\system32\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\windows\system32\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;C:\windows\system32\DRIVERS\btfilter.sys [x]
S3 BthMtpEnum;Modul pro výčet zařízení Bluetooth MTP;C:\windows\system32\DRIVERS\BthMtpEnum.sys [x]
S3 dlkmd;dlkmd;C:\windows\system32\drivers\dlkmd.sys [x]
S3 HP ProtectTools Service;HP ProtectTools Service;c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2011-01-12 18:12:06 36864]
S3 IntcDAud;Intel(R) Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;C:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;C:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;C:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;C:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;C:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 03:45:56 219496]
S3 SPUVCbv;SPUVCb Driver Service;C:\windows\system32\Drivers\SPUVCbv_x64.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys [x]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 13:05:00 451872 ----a-w- C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe
Obsah adresáře 'Naplánované úlohy'
2011-12-01 C:\windows\Tasks\HPCeeScheduleForGTR-HP$.job
- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15:40 . 2010-09-14 05:15:40]
2011-11-25 C:\windows\Tasks\HPCeeScheduleForGTR.job
- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15:40 . 2010-09-14 05:15:40]
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPPowerAssistant"="C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe" [2011-01-27 01:10:56 13880]
"AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [2011-01-07 03:07:10 615584]
"AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-01-07 03:07:00 379040]
"IgfxTray"="C:\windows\system32\igfxtray.exe" [2011-01-27 06:15:52 167960]
"HotKeysCmds"="C:\windows\system32\hkcmd.exe" [2011-01-27 06:15:38 391704]
"Persistence"="C:\windows\system32\igfxpers.exe" [2011-01-27 06:15:48 418328]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" [2011-01-27 09:52:00 835072]
"MfeEpePcMonitor"="C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" [2011-02-09 18:51:36 200704]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 10:03:04 4035152]
"combofix"="C:\ComboFix\CF4370.3XE" [2010-11-20 13:24:33 345088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll
------- Doplňkový sken -------
uStart Page = hxxp://www.searchqu.com/406
uLocal Page = C:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com?pc=CMNTDF
mLocal Page = C:\Windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: DhcpNameServer = 192.168.1.1 192.168.168.1
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Toolbar-10 - (no file)
Wow6432Node-HKCU-Run-RGSC - C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
Toolbar-10 - (no file)
HKLM-Run-SynTPEnh - C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-CyberLink PowerDVD 11.0.1620.51 - C:\Program Files (x86)\CyberLink\PowerDVD11\odinstalovat_cz.exe
AddRemove-{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} - C:\Program Files (x86)\InstallShield Installation Information\{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}\setup.exe
ComboFix 11-12-19.01 - GTR 19.12.2011 10:15:47.3.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.8126.5349 [GMT 1:00]
Spuštěný z: C:\Users\GTR\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
C:\windows\security\Database\tmp.edb
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-19 do 2011-12-19 )))))))))))))))))))))))))))))))
2011-12-19 09:21:02 . 2011-12-19 09:21:02 -------- d-----w- C:\Users\Default\AppData\Local\temp
2011-12-16 13:36:52 . 2011-12-16 13:36:52 -------- d-----w- C:\Users\GTR\AppData\Local\PowerDVDCox
2011-12-16 13:36:51 . 2011-12-16 13:36:51 -------- d-----w- C:\Users\GTR\AppData\Local\PowerDVDCinema
2011-12-16 13:32:51 . 2011-12-16 13:32:51 -------- d-----w- C:\Program Files (x86)\Common Files\CyberLink
2011-12-16 13:32:44 . 2011-12-16 13:33:53 505128 ----a-w- C:\windows\SysWow64\msvcp71.dll
2011-12-16 13:32:44 . 2011-12-16 13:33:53 353576 ----a-w- C:\windows\SysWow64\msvcr71.dll
2011-12-16 12:15:54 . 2011-12-16 12:15:54 -------- d-----w- C:\Users\GTR\AppData\Local\Apps
2011-12-16 12:15:53 . 2011-12-16 20:39:14 -------- d-----w- C:\Users\GTR\AppData\Local\Deployment
2011-12-15 10:17:00 . 2011-12-15 12:13:54 -------- d-----w- C:\wamp
2011-12-15 10:12:43 . 2011-12-15 10:12:43 -------- d-----w- C:\Users\GTR\AppData\Local\Windows Live
2011-12-15 02:34:39 . 2011-12-15 02:34:39 0 ----a-w- C:\windows\SysWow64\sho8A4D.tmp
2011-12-14 20:43:00 . 2011-11-05 05:32:50 2048 ----a-w- C:\windows\system32\tzres.dll
2011-12-14 20:43:00 . 2011-11-05 04:26:03 2048 ----a-w- C:\windows\SysWow64\tzres.dll
2011-12-14 20:41:58 . 2011-11-05 03:32:47 1638912 ----a-w- C:\windows\system32\mshtml.tlb
2011-12-14 20:41:58 . 2011-11-05 02:48:51 1638912 ----a-w- C:\windows\SysWow64\mshtml.tlb
2011-12-14 20:41:46 . 2011-11-24 04:52:09 3145216 ----a-w- C:\windows\system32\win32k.sys
2011-12-14 20:41:41 . 2011-10-15 06:31:56 723456 ----a-w- C:\windows\system32\EncDec.dll
2011-12-14 20:41:41 . 2011-10-15 05:38:59 534528 ----a-w- C:\windows\SysWow64\EncDec.dll
2011-12-12 11:06:45 . 2011-12-16 21:25:36 -------- d-----w- C:\Users\GTR\AppData\Roaming\FileZilla
2011-12-12 11:06:27 . 2011-12-12 11:06:36 -------- d-----w- C:\Program Files (x86)\FileZilla FTP Client
2011-12-11 10:53:21 . 2011-12-11 10:53:21 -------- d-----w- C:\windows\Sun
2011-12-11 10:52:55 . 2011-12-11 10:52:55 -------- d-----w- C:\Program Files (x86)\Common Files\Java
2011-12-11 10:52:30 . 2011-12-11 10:51:54 472808 ----a-w- C:\windows\SysWow64\deployJava1.dll
2011-12-11 10:51:49 . 2011-12-11 10:51:49 -------- d-----w- C:\Program Files (x86)\Java
2011-12-07 19:15:59 . 2011-12-07 19:15:59 -------- d-----w- C:\Users\GTR\AppData\Roaming\PlatinumHideIP
2011-12-07 19:15:59 . 2011-12-07 19:15:59 -------- d-----w- C:\ProgramData\PlatinumHideIP
2011-12-07 19:15:14 . 2011-12-07 19:15:18 -------- d-----w- C:\Program Files (x86)\PlatinumHideIP
2011-12-07 19:04:35 . 2011-12-07 19:04:35 -------- d-----w- C:\Users\GTR\AppData\Roaming\FreeHideIP
2011-12-07 19:04:35 . 2011-12-07 19:04:35 -------- d-----w- C:\ProgramData\FreeHideIP
2011-11-30 07:54:04 . 2006-01-17 20:00:18 14008 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\DOM.JS
2011-11-30 07:54:04 . 2006-01-17 20:00:14 14643 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\FPLIB.JS
2011-11-30 07:54:04 . 2006-01-17 20:00:10 12235 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\GETOBJ.JS
2011-11-30 07:54:04 . 2006-01-17 19:58:24 18866 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\PRELOAD.JS
2011-11-30 07:54:04 . 2006-01-17 19:58:20 18466 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\SETTEXT.JS
2011-11-30 07:54:04 . 2006-01-17 19:57:28 22188 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\STRINGS.JS
2011-11-30 07:54:04 . 2006-01-17 19:56:54 11964 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\_JMPMENU.JS
2011-11-30 07:54:04 . 2006-01-17 19:56:48 15579 ----a-w- C:\Users\GTR\AppData\Roaming\Microsoft\SharePoint Designer\Behaviors\Actions\_PRELOAD.JS
2011-11-20 23:45:39 . 2011-12-18 21:42:04 -------- d-----w- C:\Users\GTR\AppData\Roaming\HLSW
2011-11-20 23:45:39 . 2011-11-20 23:45:46 -------- d-s---w- C:\Program Files (x86)\HLSW
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-12-18 19:51:41 . 2011-10-26 08:06:52 214520 ----a-w- C:\windows\SysWow64\PnkBstrB.xtr
2011-12-18 19:51:41 . 2011-10-25 11:36:18 214520 ----a-w- C:\windows\SysWow64\PnkBstrB.exe
2011-12-18 19:49:16 . 2011-10-25 11:36:18 214520 ----a-w- C:\windows\SysWow64\PnkBstrB.ex0
2011-11-18 01:11:03 . 2011-11-18 01:11:03 0 ----a-w- C:\windows\SysWow64\sho57FB.tmp
2011-11-17 19:02:03 . 2011-10-25 11:36:16 75136 ----a-w- C:\windows\SysWow64\PnkBstrA.exe
2011-11-01 18:08:44 . 2011-11-01 18:08:44 2434856 ----a-w- C:\windows\SysWow64\pbsvc_bc2.exe
2011-10-25 11:53:12 . 2011-10-25 11:53:12 21832 ----a-w- C:\windows\system32\drivers\hamachi.sys
2011-10-25 11:36:15 . 2011-10-25 11:36:15 682280 ----a-w- C:\windows\SysWow64\pbsvc.exe
2011-10-23 11:53:14 . 2009-07-14 02:36:51 175616 ----a-w- C:\windows\system32\msclmd.dll
2011-10-23 11:53:14 . 2009-07-14 02:36:51 152576 ----a-w- C:\windows\SysWow64\msclmd.dll
2011-10-22 23:17:39 . 2011-10-22 23:17:39 0 ----a-w- C:\windows\SysWow64\shoA636.tmp
2011-09-30 15:28:10 . 2011-09-30 15:28:10 0 ----a-w- C:\windows\SysWow64\sho45BD.tmp
2011-09-29 16:29:28 . 2011-11-09 08:04:42 1923952 ----a-w- C:\windows\system32\drivers\tcpip.sys
2011-09-27 02:39:24 . 2011-10-25 11:58:41 286208 ----a-w- C:\windows\SysWow64\binkw32.dll
2011-09-26 06:15:46 . 2011-09-26 06:15:46 0 ----a-w- C:\windows\SysWow64\sho8279.tmp
2011-09-25 07:23:33 . 2011-09-25 07:23:33 178800 ----a-w- C:\windows\SysWow64\CmdLineExt_x64.dll
2011-09-24 18:18:25 . 2011-09-16 12:38:58 404640 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-24 18:06:49 . 2011-09-24 18:07:07 368912 ----a-w- C:\windows\SysWow64\VBAR332.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 252176 ----a-w- C:\windows\SysWow64\MSRD2X35.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 24848 ----a-w- C:\windows\SysWow64\MSJTER35.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 123664 ----a-w- C:\windows\SysWow64\MSJINT35.DLL
2011-09-24 18:06:49 . 2011-09-24 18:07:07 1045776 ----a-w- C:\windows\SysWow64\MSJET35.DLL
2011-09-23 09:14:53 . 2011-09-23 09:15:00 627600 ----a-w- C:\windows\system32\deployJava1.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-06-20 13:07:06 2736128]
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 07:33:30 4910912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"PDF Complete"="C:\Program Files (x86)\PDF Complete\pdfsty.exe" [2011-02-01 08:23:10 656920]
"Microsoft Default Manager"="C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 21:12:28 439568]
"QLBController"="C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-01-28 22:24:56 299576]
"File Sanitizer"="C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2011-02-07 18:41:42 12274688]
"IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-26 17:00:32 283160]
"NUSB3MON"="c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 17:53:16 113288]
"HP HD Webcam [Fixed]_Monitor"="C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe" [2010-11-26 11:31:18 267128]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-28 18:38:48 336384]
"DTRun"="c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe" [2010-11-24 18:00:06 517456]
"HPConnectionManager"="c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-04-05 18:13:58 94264]
"HPQuickWebProxy"="c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-02-11 00:44:28 76344]
"LogMeIn Hamachi Ui"="C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 14:18:14 1955208]
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 09:44:34 31072]
"NBAgent"="C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 12:53:16 1493288]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 12:06:06 254696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
GamePark klient 2.lnk - C:\Program Files\GamePark2\gpcl.exe [2011-10-25 442880]
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2011-02-03 22:09:12 75360 ----a-w- C:\Windows\System32\DeviceNP.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~2\SEARCH~1\SEARCH~1\datamngr.dll C:\PROGRA~2\SEARCH~1\SEARCH~1\IEBHO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 20:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 21:27:14 138576]
R2 XobniService;XobniService;C:\Program Files (x86)\Xobni\XobniService.exe [2011-03-07 20:48:10 62184]
R3 DAMDrv;DAMDrv;C:\windows\system32\DRIVERS\DAMDrv64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\Windows\SysWOW64\flcdlock.exe [2011-02-03 22:09:18 464480]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 18:13:46 1094712]
R3 JMCR;JMCR;C:\windows\system32\DRIVERS\jmcr.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 12:49:20 227232]
R3 nmwcdcx64;Nokia USB Generic;C:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;C:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 19:34:24 4925184]
R3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;C:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 dlkmdldr;dlkmdldr;C:\windows\system32\drivers\dlkmdldr.sys [x]
S0 MfeEpePc;MfeEpePc; [x]
S0 NBVol;Nero Backup Volume Filter Driver;C:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;C:\windows\system32\DRIVERS\NBVolUp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;C:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 10:42:00 89600]
S2 AMD External Events Utility;AMD External Events Utility;C:\windows\system32\atiesrxx.exe [x]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 03:08:38 138400]
S2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 03:06:56 53920]
S2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 13:23:26 821664]
S2 DisplayLinkService;DisplayLinkManager;C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2009-11-20 01:47:50 8547176]
S2 eamonm;eamonm;C:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 10:03:30 974944]
S2 epfwwfpr;epfwwfpr;C:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 FAH-01;Folding Service 01;C:\Program Files (x86)\Folding@Home 01\Folding@Home 01\FAH-Console.exe [2008-06-30 19:38:32 253952]
S2 FAH-02;Folding Service 02;C:\Program Files (x86)\Folding@Home 01\Folding@Home 02\FAH-Console.exe [2008-06-30 19:38:32 253952]
S2 GS In-Game Service;GS In-Game Service;C:\Program Files (x86)\GameTracker\GSInGameService.exe [2011-10-25 20:13:02 1677096]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 14:18:12 2329480]
S2 HP Power Assistant Service;HP Power Assistant Service;C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 01:11:48 131128]
S2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 13:57:34 85560]
S2 HPDayStarterService;HP DayStarter Service;c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 16:41:30 133688]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 00:07:50 94264]
S2 HPFSService;File Sanitizer for HP ProtectTools;C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 18:41:26 320000]
S2 hpHotkeyMonitor;hpHotkeyMonitor;C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-28 22:27:06 281656]
S2 hpsrv;HP Service;C:\windows\system32\Hpservice.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 17:00:00 13336]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 19:10:32 210896]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 18:28:12 1318912]
S2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-09-23 16:37:42 641832]
S2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 08:23:10 1127448]
S2 PdiService;Portrait Displays SDK Service;C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 20:42:44 113264]
S2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 03:45:44 508264]
S2 uArcCapture;ArcCapture;C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 07:43:00 502464]
S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 19:42:04 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service;C:\windows\system32\vcsFPService.exe [2011-01-22 02:36:02 3154224]
S3 amdkmdag;amdkmdag;C:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;C:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;C:\windows\system32\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\windows\system32\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;C:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\windows\system32\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\windows\system32\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\windows\system32\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;C:\windows\system32\DRIVERS\btfilter.sys [x]
S3 BthMtpEnum;Modul pro výčet zařízení Bluetooth MTP;C:\windows\system32\DRIVERS\BthMtpEnum.sys [x]
S3 dlkmd;dlkmd;C:\windows\system32\drivers\dlkmd.sys [x]
S3 HP ProtectTools Service;HP ProtectTools Service;c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2011-01-12 18:12:06 36864]
S3 IntcDAud;Intel(R) Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;C:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;C:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;C:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;C:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;C:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 03:45:56 219496]
S3 SPUVCbv;SPUVCb Driver Service;C:\windows\system32\Drivers\SPUVCbv_x64.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys [x]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 13:05:00 451872 ----a-w- C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe
Obsah adresáře 'Naplánované úlohy'
2011-12-01 C:\windows\Tasks\HPCeeScheduleForGTR-HP$.job
- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15:40 . 2010-09-14 05:15:40]
2011-11-25 C:\windows\Tasks\HPCeeScheduleForGTR.job
- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15:40 . 2010-09-14 05:15:40]
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPPowerAssistant"="C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe" [2011-01-27 01:10:56 13880]
"AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [2011-01-07 03:07:10 615584]
"AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-01-07 03:07:00 379040]
"IgfxTray"="C:\windows\system32\igfxtray.exe" [2011-01-27 06:15:52 167960]
"HotKeysCmds"="C:\windows\system32\hkcmd.exe" [2011-01-27 06:15:38 391704]
"Persistence"="C:\windows\system32\igfxpers.exe" [2011-01-27 06:15:48 418328]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" [2011-01-27 09:52:00 835072]
"MfeEpePcMonitor"="C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" [2011-02-09 18:51:36 200704]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 10:03:04 4035152]
"combofix"="C:\ComboFix\CF4370.3XE" [2010-11-20 13:24:33 345088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll
------- Doplňkový sken -------
uStart Page = hxxp://www.searchqu.com/406
uLocal Page = C:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com?pc=CMNTDF
mLocal Page = C:\Windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: DhcpNameServer = 192.168.1.1 192.168.168.1
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Toolbar-10 - (no file)
Wow6432Node-HKCU-Run-RGSC - C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
Toolbar-10 - (no file)
HKLM-Run-SynTPEnh - C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-CyberLink PowerDVD 11.0.1620.51 - C:\Program Files (x86)\CyberLink\PowerDVD11\odinstalovat_cz.exe
AddRemove-{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} - C:\Program Files (x86)\InstallShield Installation Information\{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}\setup.exe