Ok udělal jsem to a asi ještě ten log ten je tu-
ComboFix 12-06-12.01 - xXx 12.06.2012 23:20:18.2.4 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.3326.1887 [GMT 2:00]
Spuštěný z: c:\users\xXx\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\xXx\Desktop\CFScript.txt.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2639580268-3659289714-2839662224-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2639580268-3659289714-2839662224-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\1105051457\config.xml
c:\program files\ICQ6Toolbar\1105051457\Icons.bmp
c:\program files\ICQ6Toolbar\1105051457\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\1105051457\ICQToolBar.dll
c:\program files\ICQ6Toolbar\1105051457\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\1105051457\logo_small.gif
c:\program files\ICQ6Toolbar\1105051457\short.wav
c:\program files\ICQ6Toolbar\1105051457\Version.txt
c:\program files\ICQ6Toolbar\1105051457\voucher.bmp
c:\program files\ICQ6Toolbar\1105051457\voucher2.bmp
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\ICQ6Toolbar\voucher.bmp
c:\program files\ICQ6Toolbar\voucher2.bmp
c:\program files\Vuze_Remote
c:\program files\Vuze_Remote\INSTALL.LOG
c:\program files\Vuze_Remote\tbVuze.dll
c:\program files\Vuze_Remote\toolbar.cfg
c:\program files\Vuze_Remote\UNWISE.EXE
c:\program files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe
c:\users\xXx\AppData\Local\Akamai
c:\users\xXx\AppData\Local\Akamai\admintool.exe
c:\users\xXx\AppData\Local\Akamai\client.ini
c:\users\xXx\AppData\Local\Akamai\ControlPanel.exe
c:\users\xXx\AppData\Local\Akamai\ControlPanel_Installer.exe
c:\users\xXx\AppData\Local\Akamai\CplTasks.xml
c:\users\xXx\AppData\Local\Akamai\euc_state.json
c:\users\xXx\AppData\Local\Akamai\guid.ini
c:\users\xXx\AppData\Local\Akamai\installer.txt
c:\users\xXx\AppData\Local\Akamai\installer_no_upload_silent.exe
c:\users\xXx\AppData\Local\Akamai\Languages\csy.dll
c:\users\xXx\AppData\Local\Akamai\Languages\dan.dll
c:\users\xXx\AppData\Local\Akamai\Languages\deu.dll
c:\users\xXx\AppData\Local\Akamai\Languages\esp.dll
c:\users\xXx\AppData\Local\Akamai\Languages\fin.dll
c:\users\xXx\AppData\Local\Akamai\Languages\fra.dll
c:\users\xXx\AppData\Local\Akamai\Languages\chs.dll
c:\users\xXx\AppData\Local\Akamai\Languages\cht.dll
c:\users\xXx\AppData\Local\Akamai\Languages\ita.dll
c:\users\xXx\AppData\Local\Akamai\Languages\jpn.dll
c:\users\xXx\AppData\Local\Akamai\Languages\kor.dll
c:\users\xXx\AppData\Local\Akamai\Languages\nld.dll
c:\users\xXx\AppData\Local\Akamai\Languages\nor.dll
c:\users\xXx\AppData\Local\Akamai\Languages\plk.dll
c:\users\xXx\AppData\Local\Akamai\Languages\ptb.dll
c:\users\xXx\AppData\Local\Akamai\Languages\ptg.dll
c:\users\xXx\AppData\Local\Akamai\Languages\rus.dll
c:\users\xXx\AppData\Local\Akamai\Languages\sve.dll
c:\users\xXx\AppData\Local\Akamai\Languages\trk.dll
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120605_210923.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120606_052928.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120606_213504.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120607_053206.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120607_211205.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120610_153529.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120610_215025.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120611_052638.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120611_212546.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_042724.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_145907.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_150038.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_172745.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_173015.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_174426.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_180105.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_181042.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon.debug.log.120612_182337.sent
c:\users\xXx\AppData\Local\Akamai\Logs\daemon1.debug.log
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120605_203323.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120605_210923.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_053042.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_063042.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_073042.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_083043.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_093044.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_103044.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_113044.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_123045.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_133045.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_143045.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_153046.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_163046.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_173046.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_183047.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_193047.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_203048.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120606_213049.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_053318.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_063318.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_073319.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_083319.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_093320.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_103321.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_113321.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_123321.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_133321.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_143322.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_153323.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_163323.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_173323.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_183324.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_193324.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_203324.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120607_211204.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_153649.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_163650.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_173651.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_183651.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_193652.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_203652.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_213653.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120610_215025.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_052751.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_062752.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_072753.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_082753.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_092754.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_102755.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_112755.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_122755.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_132756.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_142756.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_152757.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_162757.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_172758.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_182758.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_192759.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_202759.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120611_212545.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_042845.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_052846.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_062846.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_072847.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_082848.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_092848.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_102849.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_112850.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_122850.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_132851.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_142852.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_145907.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_150212.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_160212.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_170213.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_172743.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_173222.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_174425.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_180142.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_181042.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_182410.sent
c:\users\xXx\AppData\Local\Akamai\Logs\debug.log.120612_192411.sent
c:\users\xXx\AppData\Local\Akamai\netsession_win.exe
c:\users\xXx\AppData\Local\Akamai\readme.txt
c:\users\xXx\AppData\Local\Akamai\root.pem
c:\users\xXx\AppData\Local\Akamai\rswinui.exe
c:\users\xXx\AppData\Local\Akamai\uninstall.exe
c:\users\xXx\AppData\Local\Akamai\user.dat
c:\users\xXx\AppData\Local\Facebook\Update
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\FacebookCrashHandler.exe
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\FacebookUpdate.exe
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\FacebookUpdateHelper.msi
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdate.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ar.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_bg.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_bn.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ca.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_cs.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_da.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_de.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_el.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_en-GB.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_en.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_es-419.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_es.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_et.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fa.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fi.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fil.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fr.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_gu.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hi.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hr.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hu.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_id.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_is.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_it.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_iw.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ja.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_kn.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ko.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lt.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lv.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ml.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_mr.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ms.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_nl.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_no.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_or.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pl.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-BR.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-PT.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ro.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ru.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sk.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sl.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sr.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sv.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ta.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_te.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_th.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_tr.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_uk.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ur.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_vi.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-CN.dll
c:\users\xXx\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-TW.dll
c:\users\xXx\AppData\Local\Facebook\Update\FacebookUpdate.exe
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2639580268-3659289714-2839662224-1000Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2639580268-3659289714-2839662224-1000UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Akamai
-------\Service_ICQ Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-05-12 do 2012-06-12 )))))))))))))))))))))))))))))))
.
.
2012-06-12 18:46 . 2012-06-12 18:58 -------- d-----w- C:\rsit
2012-06-12 18:46 . 2012-06-12 18:46 -------- d-----w- c:\program files\trend micro
2012-06-12 15:51 . 2012-06-12 15:51 -------- d-----w- c:\users\xXx\AppData\Local\AVG Secure Search
2012-06-12 15:48 . 2012-06-12 15:48 -------- d-----w- C:\$AVG
2012-06-12 15:21 . 2012-06-12 18:17 -------- d-----w- c:\users\xXx\AppData\Roaming\AVG2012
2012-06-12 15:19 . 2012-06-12 18:13 -------- d-----w- c:\programdata\AVG Secure Search
2012-06-12 15:19 . 2012-06-12 18:16 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2012-06-12 15:19 . 2012-06-12 18:16 -------- d-----w- c:\program files\AVG Secure Search
2012-06-12 15:18 . 2012-06-12 18:17 -------- d-----w- c:\windows\system32\drivers\AVG
2012-06-12 15:18 . 2012-06-12 18:17 -------- d-----w- c:\programdata\AVG2012
2012-06-12 15:17 . 2012-06-12 18:13 -------- d-----w- c:\program files\AVG
2012-06-12 15:06 . 2012-06-12 15:06 -------- d--h--w- c:\programdata\Common Files
2012-06-12 15:06 . 2012-06-12 18:17 -------- d-----w- c:\programdata\MFAData
2012-06-05 15:23 . 2012-06-05 16:22 -------- d-----w- c:\users\xXx\AppData\Roaming\AVI ReComp
2012-06-05 15:22 . 2012-06-12 18:17 -------- d-----w- c:\program files\Xvid
2012-06-05 15:22 . 2012-06-12 18:16 -------- d-----w- c:\program files\AviSynth 2.5
2012-06-05 15:21 . 2012-06-12 18:16 -------- d-----w- c:\program files\AVI ReComp
2012-05-24 14:20 . 2012-05-24 14:20 -------- d-----w- c:\users\xXx\AppData\Local\SniperV2
2012-05-24 13:14 . 2012-05-24 13:14 -------- d-----w- c:\users\xXx\AppData\Roaming\LolClient2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-12 21:27 . 2010-06-16 14:15 17488 ----a-w- c:\windows\gdrv.sys
2012-05-21 20:46 . 2010-06-16 16:16 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-05-21 20:45 . 2010-06-16 17:18 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-05-21 20:45 . 2010-06-16 16:15 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-04-24 16:12 . 2010-06-16 16:15 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-03-22 19:12 . 2012-03-22 19:12 4435968 ----a-w- c:\windows\system32\GPhotos.scr
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-12_20.03.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:55 . 2012-06-12 21:29 42018 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-06-16 13:48 . 2012-06-12 21:29 13672 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2639580268-3659289714-2839662224-1000_UserData.bin
- 2010-06-16 22:41 . 2012-06-12 18:23 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-16 22:41 . 2012-06-12 21:28 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-16 22:41 . 2012-06-12 18:23 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-16 22:41 . 2012-06-12 21:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2012-06-12 21:28 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2012-06-12 18:23 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-16 13:48 . 2012-06-12 21:29 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-16 13:48 . 2012-06-12 18:23 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-16 13:48 . 2012-06-12 18:23 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-16 13:48 . 2012-06-12 21:29 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-06-16 13:48 . 2012-06-12 18:23 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-16 13:48 . 2012-06-12 21:29 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-16 13:48 . 2012-06-12 18:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-16 13:48 . 2012-06-12 21:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-16 13:48 . 2012-06-12 18:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-16 13:48 . 2012-06-12 21:29 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-06-12 18:22 . 2012-06-12 21:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-12 18:22 . 2012-06-12 18:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-06-12 18:22 . 2012-06-12 21:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-06-12 18:22 . 2012-06-12 18:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-06-12 15:19 1811296 ----a-w- c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll" [2012-06-12 1811296]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2011-01-05 133432]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-12-05 3082320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-21 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2007-05-15 204800]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-07-28 9398888]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-06-12 939872]
.
c:\users\xXx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2011-6-20 0]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
Preme.exe [2011-3-2 989374]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockFree\ObjectDock.exe [2010-10-6 3768176]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BEE Service.lnk - c:\program files\V-Gear BEE\VBService.exe [2010-9-30 1393664]
GamePark klient 2.lnk - c:\program files\GamePark2\gpcl.exe [2011-9-3 409088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockFree\ODMenu.dll" [2010-10-04 511344]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-16 136176]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [x]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 cpuz130;cpuz130;c:\users\xXx\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-16 136176]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-10 23120]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-10 295248]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-03-09 176128]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-08 294400]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 140224]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
S2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
S2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 1373576]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-06-12 909152]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-03-09 7723008]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-03-09 239616]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-10 134736]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-10 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-30 187392]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.cz/
uDefault_Search_URL = hxxp://
www.google.com/ie
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Stáhnout odkaz s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Stáhnout všechna videa s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 172.16.0.5
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
AddRemove-Vuze_Remote Toolbar - c:\progra~1\VUZE_R~1\UNWISE.EXE
AddRemove-Akamai - c:\users\xXx\AppData\Local\Akamai\uninstall.exe
.
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2412)
c:\windows\System32\ieframe.dll
c:\program files\Stardock\ObjectDockFree\ODMenu.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\ArcSoft\Magic-i 3\uMgiSvr.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\taskhost.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2012-06-12 23:34:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-06-12 21:34
ComboFix2.txt 2012-06-12 20:07
.
Před spuštěním: Volných bajtů: 60 964 536 320
Po spuštění: Volných bajtů: 60 717 031 424
.
- - End Of File - - C9D165428C380750BB801692FBD87949