Nefunkční Mozilla Firefox
Napsal: 08 črc 2012 09:48
Dobrý den, nefunguje mi mozilla, jiné prohlížeče Google chrome, IE ano. Nefunguje doma jen na jednom PC, na dalším stolním PC a 2 noteboocích doma funguje. Zkoušela jsem dle návodu vypnout firewall bránu, adresu proxy serveru neznám, není zadaná ani na IE, tak jsem zvolila v Možnosti připojení *bez proxy adresy* ( neformuluji asi přesně, neznám formulace přesně zpaměti). Podle další rady jsem vymazala v historii cookies, mezipaměť. Restarovala Mozilu, obnovení Mozilly. Odinstalovala a znovu nainstalovala Mozillu. Potíže stále trvají. Mozilla se otevře, ale když chci otevřit jakoukoliv stránku, zastaví se kolovrátek a několik minut stojí ztuhlý, pak se požadovaný krok či stránka zobrazí a zase stojí.
Ještě chci dodat, moje dcera i přes zákaz neustále chodí na můj PC, neustále něco stahuje a kliká rychle bez čtení na bůhvíco. Zjistila jsem, že nainstalovala nějaký zřejmě zrychlovač prohlížení pod názvem SpeedMaximizer, kde byl nalezen vir. Dočetla jsem se, že právě tyto malware napadají Firefox. Provedla jsem kompletní skenování NODem32. Byl nalezen tento vir, dán do karantény a program jsem odinstalovala. Předtím byl nalezen vir v objektu Toolbar.Zugo.
Spustila jsem ComboFix, restartovala a stále problém...tady je protokol. Pokud se v tom někdo vyzná, prosím o pomoc
ComboFix 12-07-07.04 - Zbyněk 08.07.2012 10:04:18.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2037.1055 [GMT 2:00]
Spuštěný z: c:\users\Zbynýk\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Complitly
c:\program files\Complitly\FireFoxExtension.exe
c:\program files\Complitly\chrome\autocompleteprochrome.crx
c:\program files\Complitly\InstTracker.exe
c:\program files\Complitly\support@Complitly.com\defaults\preferences\predictad.js
c:\program files\Complitly\support@Complitly.com\chrome.manifest
c:\program files\Complitly\support@Complitly.com\chrome\content\appIcon.png
c:\program files\Complitly\support@Complitly.com\chrome\content\browserOverlay.xul
c:\program files\Complitly\support@Complitly.com\chrome\content\options.js
c:\program files\Complitly\support@Complitly.com\chrome\content\options.xul
c:\program files\Complitly\support@Complitly.com\chrome\content\utils.js
c:\program files\Complitly\support@Complitly.com\install.rdf
c:\program files\Complitly\unins000.dat
c:\program files\Complitly\unins000.exe
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoods.crx
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoods.png
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsApp.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\uninstall.exe
c:\program files\facemoods.com\sqlite3.dll
c:\program files\FYTDL DB Toolbar\tbHElper.dll
c:\program files\Your Product\Uninstall
c:\program files\Your Product\Uninstall\IRIMG1.JPG
c:\program files\Your Product\Uninstall\IRIMG2.JPG
c:\program files\Your Product\Uninstall\uninstall.dat
c:\program files\Your Product\Uninstall\uninstall.xml
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-08 do 2012-07-08 )))))))))))))))))))))))))))))))
.
.
2012-07-08 08:12 . 2012-07-08 08:12 -------- d-----w- c:\users\Lucka\AppData\Local\temp
2012-07-08 08:12 . 2012-07-08 08:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-08 08:11 . 2012-07-08 08:11 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C669707A-03F4-4C3A-9E05-FB2E03D627DF}\offreg.dll
2012-07-07 21:53 . 2012-07-07 21:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{54084184-998E-49D6-83DB-B78FE77F283C}
2012-07-07 21:53 . 2012-07-07 21:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{07B7E62A-F48E-44C0-8CF4-AF6D379DBB8E}
2012-07-07 21:50 . 2012-07-07 21:50 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Google
2012-07-07 19:08 . 2012-07-07 19:08 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Opera
2012-07-07 19:08 . 2012-07-07 19:08 -------- d-----w- c:\users\Zbyněk\AppData\Local\Opera
2012-07-07 19:08 . 2012-07-07 19:26 -------- d-----w- c:\program files\Opera
2012-07-07 10:24 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-07-07 09:53 . 2012-07-07 09:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{9F3A2462-D3E3-4423-A6E2-CEF460CBEB07}
2012-07-07 09:52 . 2012-07-07 09:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{1DEA15E0-FA14-402C-BC0E-C530DBC141DF}
2012-07-07 08:08 . 2012-07-07 08:09 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Mozilla
2012-07-06 07:00 . 2012-07-07 11:10 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 07:00 . 2012-07-07 11:10 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-06 05:56 . 2012-06-18 01:14 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C669707A-03F4-4C3A-9E05-FB2E03D627DF}\mpengine.dll
2012-07-04 11:26 . 2012-07-04 11:26 -------- d-----w- c:\users\Zbyněk\AppData\Local\{9C133395-9F77-4EB4-A5F7-C3CE09B8ABC7}
2012-07-04 11:26 . 2012-07-04 11:26 -------- d-----w- c:\users\Zbyněk\AppData\Local\{69201341-AECA-4526-8E3A-BE6479CCA3AC}
2012-07-04 11:25 . 2012-07-04 11:25 -------- d-----w- c:\users\Zbyněk\AppData\Local\{DD3DE33E-4828-4BB0-A953-9B1A66FA3950}
2012-07-03 07:58 . 2012-07-03 07:58 -------- d-----w- c:\users\Zbyněk\AppData\Local\{A955CB8F-41A4-44B7-BB9E-D4765C858FE5}
2012-07-03 07:58 . 2012-07-03 07:58 -------- d-----w- c:\users\Zbyněk\AppData\Local\{517D1A1C-2840-4D03-87EA-41912D822655}
2012-07-02 06:06 . 2012-07-02 06:07 -------- d-----w- c:\users\Zbyněk\AppData\Local\{FA1DCECA-AEC3-4517-ABD6-8742B9D0D065}
2012-07-02 06:06 . 2012-07-02 06:06 -------- d-----w- c:\users\Zbyněk\AppData\Local\{615884E5-E47C-4D7C-851E-40C8EBE7EEA0}
2012-07-01 17:03 . 2012-07-01 17:04 -------- d-----w- c:\users\Zbyněk\AppData\Local\{3E4BF738-4A86-4DCE-872D-2D57ED53A6E9}
2012-07-01 17:03 . 2012-07-01 17:03 -------- d-----w- c:\users\Zbyněk\AppData\Local\{438BC705-7B99-435D-A416-E08F6B9BD4D4}
2012-06-27 09:01 . 2012-06-27 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{A065E62F-0680-402D-B99B-AF39EF8B1DB6}
2012-06-27 09:01 . 2012-06-27 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{096018E4-B927-40F3-9B61-B8C5CECBA5C3}
2012-06-26 18:59 . 2012-06-26 19:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{BEFD7703-9B14-49B8-A055-84A35DBBEE50}
2012-06-26 18:59 . 2012-06-26 18:59 -------- d-----w- c:\users\Zbyněk\AppData\Local\{BF57035F-6394-4042-9207-0C7CC2AAE00B}
2012-06-26 12:21 . 2012-06-26 12:21 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\SpeedyPC Software
2012-06-26 12:21 . 2012-06-26 12:21 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\DriverCure
2012-06-26 12:21 . 2012-07-07 09:46 -------- d-----w- c:\programdata\SpeedyPC Software
2012-06-26 12:12 . 2012-06-26 12:50 737280 ----a-w- c:\windows\iun6002.exe
2012-06-26 12:12 . 2012-06-26 12:50 -------- d-----w- c:\windows\system32\languages
2012-06-26 11:49 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-26 11:49 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-26 11:49 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-26 11:49 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-26 11:49 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-26 11:49 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-26 11:49 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-26 11:48 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-26 11:48 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-26 11:38 . 2012-06-26 11:38 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Media Player Classic
2012-06-26 11:10 . 2012-06-26 12:50 -------- d-----w- c:\program files\Codec Pack - All In 1
2012-06-26 11:00 . 2012-06-26 11:44 -------- d-----w- c:\program files\K-Lite Codec Pack
2012-06-26 08:53 . 2012-06-26 08:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8509065D-F5C5-4D4E-AFD3-3304AB89827F}
2012-06-26 08:52 . 2012-06-26 08:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{74352A15-1A5C-4C1E-B4F1-B20BD6E31D61}
2012-06-26 08:20 . 2012-06-26 08:20 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-06-24 20:30 . 2012-06-24 20:30 -------- d-----w- c:\program files\MP4Converter
2012-06-24 11:42 . 2012-06-24 11:42 -------- d-----w- c:\users\Zbyněk\AppData\Local\{99EF1749-D9BC-4871-BDA3-8930A8057C7B}
2012-06-24 11:42 . 2012-06-24 11:42 -------- d-----w- c:\users\Zbyněk\AppData\Local\{181EC35E-3A3E-43F5-8B48-3DE84CBAD696}
2012-06-22 07:02 . 2012-06-22 07:02 -------- d-----w- c:\users\Zbyněk\AppData\Local\{88F9A226-29CB-4CB7-9FF9-3268BB89BFEF}
2012-06-22 07:02 . 2012-06-22 07:02 -------- d-----w- c:\users\Zbyněk\AppData\Local\{CBDEFBB1-8F54-4385-A9A2-EAF42DCA2B8D}
2012-06-21 07:00 . 2012-06-21 07:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{474E8549-709E-4991-B09E-263AAE919582}
2012-06-21 07:00 . 2012-06-21 07:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8DC73E52-28B9-4689-93F8-A11594F2699E}
2012-06-19 07:24 . 2012-06-19 07:24 -------- d-----w- c:\users\Zbyněk\AppData\Local\{1AF6C19B-DD77-4E36-B0D2-022D4D07D1EC}
2012-06-19 07:24 . 2012-06-19 07:24 -------- d-----w- c:\users\Zbyněk\AppData\Local\{D84A192D-85E8-4461-A8DA-14BC8DC57895}
2012-06-18 06:44 . 2012-06-18 06:44 -------- d-----w- c:\users\Zbyněk\AppData\Local\{E43BECEA-DACA-483D-8ADB-F08B87D396AA}
2012-06-17 16:18 . 2012-06-17 16:18 -------- d-----w- c:\users\Zbyněk\AppData\Local\{C59FF2CA-C2FB-4CA3-8B0D-448FAA6E5C62}
2012-06-17 16:18 . 2012-06-17 16:18 -------- d-----w- c:\users\Zbyněk\AppData\Local\{437E96FB-7F75-4BA5-87D9-77B47B95C5A6}
2012-06-17 07:46 . 2012-06-17 07:46 -------- d-----w- c:\users\Zbyněk\AppData\Local\Macromedia
2012-06-15 08:29 . 2012-06-15 08:29 -------- d-----w- c:\users\Zbyněk\AppData\Local\{169B9964-8E80-4EF2-8EA1-10673E00C3C0}
2012-06-14 04:53 . 2012-04-28 03:17 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-14 04:53 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\system32\msi.dll
2012-06-14 04:53 . 2012-05-15 01:05 2343936 ----a-w- c:\windows\system32\win32k.sys
2012-06-14 04:53 . 2012-04-26 04:45 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-06-14 04:53 . 2012-04-26 04:45 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-06-14 04:53 . 2012-04-26 04:41 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-14 04:53 . 2012-05-01 04:44 164352 ----a-w- c:\windows\system32\profsvc.dll
2012-06-14 04:53 . 2012-04-24 04:36 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-14 04:53 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\system32\crypt32.dll
2012-06-14 04:53 . 2012-04-24 04:36 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-14 04:04 . 2012-06-14 04:04 -------- d-----w- c:\users\Zbyněk\AppData\Local\{EE8C82C0-38C8-4E2B-92C1-3E7D172419A6}
2012-06-14 04:03 . 2012-06-14 04:04 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8E815DD7-FBB0-458C-A847-F4FF9D0A8155}
2012-06-13 20:06 . 2012-06-13 20:06 -------- d-----w- c:\users\Zbyněk\AppData\Local\{47B0937E-AED0-4827-A781-EE6B382C2244}
2012-06-13 05:15 . 2012-06-13 05:15 -------- d-----w- c:\users\Zbyněk\AppData\Local\{0DDE7980-707F-4204-8029-31A52A712C54}
2012-06-13 05:15 . 2012-06-13 05:15 -------- d-----w- c:\users\Zbyněk\AppData\Local\{A00520B7-6A0F-4605-B5BE-8B21B4FEE2EE}
2012-06-12 10:31 . 2012-06-12 10:31 -------- d-----w- c:\users\Zbyněk\AppData\Local\{04053703-0CC6-456E-85E0-CB68A0D55664}
2012-06-12 10:31 . 2012-06-12 10:31 -------- d-----w- c:\users\Zbyněk\AppData\Local\{95DE0F38-DE5C-46C9-89E5-C1766C06BBAD}
2012-06-11 08:09 . 2012-06-11 08:09 -------- d-----w- c:\users\Zbyněk\AppData\Local\{7861CCF0-2FEE-4DB1-B036-05955B43E4C4}
2012-06-11 08:09 . 2012-06-11 08:09 -------- d-----w- c:\users\Zbyněk\AppData\Local\{F03B8DDB-74E5-45FC-B934-3FC9D7A4E72E}
2012-06-10 18:25 . 2012-06-10 18:26 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8D44C865-9A75-4543-9BF3-31E50D710245}
2012-06-10 18:25 . 2012-06-10 18:25 -------- d-----w- c:\users\Zbyněk\AppData\Local\{AFD26AB6-9B85-4F44-ABAC-6F27A6AE2DC3}
2012-06-09 20:00 . 2012-06-09 20:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{FA1238AF-723D-4FE4-8B2B-76EAD0C7F402}
2012-06-09 20:00 . 2012-06-09 20:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{44DF5E7A-D542-4766-8B31-ABCAA2D8BBE7}
2012-06-09 07:13 . 2012-06-09 07:13 -------- d-----w- c:\users\Zbyněk\AppData\Local\{110A0EAC-5D21-4B2B-84EE-01558EA27A22}
2012-06-09 07:13 . 2012-06-09 07:13 -------- d-----w- c:\users\Zbyněk\AppData\Local\{E4DF1BB1-1B06-4F5C-B661-67B624FC7E06}
2012-06-08 09:01 . 2012-06-08 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{96A58D79-12FE-4428-A3F1-4003C6E1B257}
2012-06-08 09:01 . 2012-06-08 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{64FC1883-A02D-4858-8066-41B6D7B00D0A}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-14 22:19 . 2012-07-07 21:00 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"ALLUpdate"="c:\program files\OpenSubtitlesPlayer\ALLUpdate.exe" [2011-02-26 1022464]
"Facebook Update"="c:\users\Zbyněk\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-09-30 137536]
"Akamai NetSession Interface"="c:\users\Zbyněk\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
"NokiaSuite.exe"="c:\program files\Nokia\Nokia Suite\NokiaSuite.exe" [2012-01-10 1083264]
"InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-10-11 1179648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-24 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"YouCam Mirror Tray icon"="c:\program files\CyberLink\YouCam\YouCamTray.exe" [2009-06-11 162912]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"Print2PDF Print Monitor"="c:\program files\Software602\Print2PDF\Print2PDF.exe" [2011-04-12 222776]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2011-06-15 273544]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Clearblue.lnk - c:\windows\Installer\{D99F7568-803E-4C13-80DD-9403CD34F5F3}\_F015326B9D6121FF10D37F.exe [2011-7-13 370070]
Philips GoGear VIBE Device Manager.lnk - c:\philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe [2011-5-6 1611152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 602XML Updater;602Updater;c:\program files\Common Files\soft602\602updsvc\602updsvc.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S3 AsAudioDevice_349;AsAudioDevice_349;c:\windows\system32\drivers\AsAudioDevice_349.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2012-07-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-06 11:10]
.
2012-07-08 c:\windows\Tasks\FinalTorrent Update Checker.job
- c:\program files\FinalTorrent\FTCheckForUpdates.exe [2011-05-24 14:50]
.
2012-07-08 c:\windows\Tasks\FreeFileViewerUpdateChecker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2011-07-02 13:24]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-07 19:00]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-07 19:00]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.bigseekpro.com/howfytdl/{3B00801A-3 ... 6ECF289658}
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Zbyněk\AppData\Roaming\Mozilla\Firefox\Profiles\rvnxzunm.default-1341695351180\
FF - prefs.js: browser.startup.homepage - http://www.seznam.cz
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe
AddRemove-Complitly_is1 - c:\program files\Complitly\unins000.exe
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_80c2ffa.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-07-08 10:15:01
ComboFix-quarantined-files.txt 2012-07-08 08:15
.
Před spuštěním: Volných bajtů: 169 411 903 488
Po spuštění: Volných bajtů: 169 315 930 112
.
- - End Of File - - 1A5F44689B28FCF7856A2701F61B139E
Ještě chci dodat, moje dcera i přes zákaz neustále chodí na můj PC, neustále něco stahuje a kliká rychle bez čtení na bůhvíco. Zjistila jsem, že nainstalovala nějaký zřejmě zrychlovač prohlížení pod názvem SpeedMaximizer, kde byl nalezen vir. Dočetla jsem se, že právě tyto malware napadají Firefox. Provedla jsem kompletní skenování NODem32. Byl nalezen tento vir, dán do karantény a program jsem odinstalovala. Předtím byl nalezen vir v objektu Toolbar.Zugo.
Spustila jsem ComboFix, restartovala a stále problém...tady je protokol. Pokud se v tom někdo vyzná, prosím o pomoc
ComboFix 12-07-07.04 - Zbyněk 08.07.2012 10:04:18.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2037.1055 [GMT 2:00]
Spuštěný z: c:\users\Zbynýk\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Complitly
c:\program files\Complitly\FireFoxExtension.exe
c:\program files\Complitly\chrome\autocompleteprochrome.crx
c:\program files\Complitly\InstTracker.exe
c:\program files\Complitly\support@Complitly.com\defaults\preferences\predictad.js
c:\program files\Complitly\support@Complitly.com\chrome.manifest
c:\program files\Complitly\support@Complitly.com\chrome\content\appIcon.png
c:\program files\Complitly\support@Complitly.com\chrome\content\browserOverlay.xul
c:\program files\Complitly\support@Complitly.com\chrome\content\options.js
c:\program files\Complitly\support@Complitly.com\chrome\content\options.xul
c:\program files\Complitly\support@Complitly.com\chrome\content\utils.js
c:\program files\Complitly\support@Complitly.com\install.rdf
c:\program files\Complitly\unins000.dat
c:\program files\Complitly\unins000.exe
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoods.crx
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoods.png
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsApp.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe
c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.4.17.5\uninstall.exe
c:\program files\facemoods.com\sqlite3.dll
c:\program files\FYTDL DB Toolbar\tbHElper.dll
c:\program files\Your Product\Uninstall
c:\program files\Your Product\Uninstall\IRIMG1.JPG
c:\program files\Your Product\Uninstall\IRIMG2.JPG
c:\program files\Your Product\Uninstall\uninstall.dat
c:\program files\Your Product\Uninstall\uninstall.xml
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-08 do 2012-07-08 )))))))))))))))))))))))))))))))
.
.
2012-07-08 08:12 . 2012-07-08 08:12 -------- d-----w- c:\users\Lucka\AppData\Local\temp
2012-07-08 08:12 . 2012-07-08 08:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-08 08:11 . 2012-07-08 08:11 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C669707A-03F4-4C3A-9E05-FB2E03D627DF}\offreg.dll
2012-07-07 21:53 . 2012-07-07 21:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{54084184-998E-49D6-83DB-B78FE77F283C}
2012-07-07 21:53 . 2012-07-07 21:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{07B7E62A-F48E-44C0-8CF4-AF6D379DBB8E}
2012-07-07 21:50 . 2012-07-07 21:50 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Google
2012-07-07 19:08 . 2012-07-07 19:08 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Opera
2012-07-07 19:08 . 2012-07-07 19:08 -------- d-----w- c:\users\Zbyněk\AppData\Local\Opera
2012-07-07 19:08 . 2012-07-07 19:26 -------- d-----w- c:\program files\Opera
2012-07-07 10:24 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-07-07 09:53 . 2012-07-07 09:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{9F3A2462-D3E3-4423-A6E2-CEF460CBEB07}
2012-07-07 09:52 . 2012-07-07 09:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{1DEA15E0-FA14-402C-BC0E-C530DBC141DF}
2012-07-07 08:08 . 2012-07-07 08:09 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Mozilla
2012-07-06 07:00 . 2012-07-07 11:10 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 07:00 . 2012-07-07 11:10 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-06 05:56 . 2012-06-18 01:14 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C669707A-03F4-4C3A-9E05-FB2E03D627DF}\mpengine.dll
2012-07-04 11:26 . 2012-07-04 11:26 -------- d-----w- c:\users\Zbyněk\AppData\Local\{9C133395-9F77-4EB4-A5F7-C3CE09B8ABC7}
2012-07-04 11:26 . 2012-07-04 11:26 -------- d-----w- c:\users\Zbyněk\AppData\Local\{69201341-AECA-4526-8E3A-BE6479CCA3AC}
2012-07-04 11:25 . 2012-07-04 11:25 -------- d-----w- c:\users\Zbyněk\AppData\Local\{DD3DE33E-4828-4BB0-A953-9B1A66FA3950}
2012-07-03 07:58 . 2012-07-03 07:58 -------- d-----w- c:\users\Zbyněk\AppData\Local\{A955CB8F-41A4-44B7-BB9E-D4765C858FE5}
2012-07-03 07:58 . 2012-07-03 07:58 -------- d-----w- c:\users\Zbyněk\AppData\Local\{517D1A1C-2840-4D03-87EA-41912D822655}
2012-07-02 06:06 . 2012-07-02 06:07 -------- d-----w- c:\users\Zbyněk\AppData\Local\{FA1DCECA-AEC3-4517-ABD6-8742B9D0D065}
2012-07-02 06:06 . 2012-07-02 06:06 -------- d-----w- c:\users\Zbyněk\AppData\Local\{615884E5-E47C-4D7C-851E-40C8EBE7EEA0}
2012-07-01 17:03 . 2012-07-01 17:04 -------- d-----w- c:\users\Zbyněk\AppData\Local\{3E4BF738-4A86-4DCE-872D-2D57ED53A6E9}
2012-07-01 17:03 . 2012-07-01 17:03 -------- d-----w- c:\users\Zbyněk\AppData\Local\{438BC705-7B99-435D-A416-E08F6B9BD4D4}
2012-06-27 09:01 . 2012-06-27 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{A065E62F-0680-402D-B99B-AF39EF8B1DB6}
2012-06-27 09:01 . 2012-06-27 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{096018E4-B927-40F3-9B61-B8C5CECBA5C3}
2012-06-26 18:59 . 2012-06-26 19:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{BEFD7703-9B14-49B8-A055-84A35DBBEE50}
2012-06-26 18:59 . 2012-06-26 18:59 -------- d-----w- c:\users\Zbyněk\AppData\Local\{BF57035F-6394-4042-9207-0C7CC2AAE00B}
2012-06-26 12:21 . 2012-06-26 12:21 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\SpeedyPC Software
2012-06-26 12:21 . 2012-06-26 12:21 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\DriverCure
2012-06-26 12:21 . 2012-07-07 09:46 -------- d-----w- c:\programdata\SpeedyPC Software
2012-06-26 12:12 . 2012-06-26 12:50 737280 ----a-w- c:\windows\iun6002.exe
2012-06-26 12:12 . 2012-06-26 12:50 -------- d-----w- c:\windows\system32\languages
2012-06-26 11:49 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-26 11:49 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-26 11:49 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-26 11:49 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-26 11:49 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-26 11:49 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-26 11:49 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-26 11:48 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-26 11:48 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-26 11:38 . 2012-06-26 11:38 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\Media Player Classic
2012-06-26 11:10 . 2012-06-26 12:50 -------- d-----w- c:\program files\Codec Pack - All In 1
2012-06-26 11:00 . 2012-06-26 11:44 -------- d-----w- c:\program files\K-Lite Codec Pack
2012-06-26 08:53 . 2012-06-26 08:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8509065D-F5C5-4D4E-AFD3-3304AB89827F}
2012-06-26 08:52 . 2012-06-26 08:53 -------- d-----w- c:\users\Zbyněk\AppData\Local\{74352A15-1A5C-4C1E-B4F1-B20BD6E31D61}
2012-06-26 08:20 . 2012-06-26 08:20 -------- d-----w- c:\users\Zbyněk\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-06-24 20:30 . 2012-06-24 20:30 -------- d-----w- c:\program files\MP4Converter
2012-06-24 11:42 . 2012-06-24 11:42 -------- d-----w- c:\users\Zbyněk\AppData\Local\{99EF1749-D9BC-4871-BDA3-8930A8057C7B}
2012-06-24 11:42 . 2012-06-24 11:42 -------- d-----w- c:\users\Zbyněk\AppData\Local\{181EC35E-3A3E-43F5-8B48-3DE84CBAD696}
2012-06-22 07:02 . 2012-06-22 07:02 -------- d-----w- c:\users\Zbyněk\AppData\Local\{88F9A226-29CB-4CB7-9FF9-3268BB89BFEF}
2012-06-22 07:02 . 2012-06-22 07:02 -------- d-----w- c:\users\Zbyněk\AppData\Local\{CBDEFBB1-8F54-4385-A9A2-EAF42DCA2B8D}
2012-06-21 07:00 . 2012-06-21 07:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{474E8549-709E-4991-B09E-263AAE919582}
2012-06-21 07:00 . 2012-06-21 07:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8DC73E52-28B9-4689-93F8-A11594F2699E}
2012-06-19 07:24 . 2012-06-19 07:24 -------- d-----w- c:\users\Zbyněk\AppData\Local\{1AF6C19B-DD77-4E36-B0D2-022D4D07D1EC}
2012-06-19 07:24 . 2012-06-19 07:24 -------- d-----w- c:\users\Zbyněk\AppData\Local\{D84A192D-85E8-4461-A8DA-14BC8DC57895}
2012-06-18 06:44 . 2012-06-18 06:44 -------- d-----w- c:\users\Zbyněk\AppData\Local\{E43BECEA-DACA-483D-8ADB-F08B87D396AA}
2012-06-17 16:18 . 2012-06-17 16:18 -------- d-----w- c:\users\Zbyněk\AppData\Local\{C59FF2CA-C2FB-4CA3-8B0D-448FAA6E5C62}
2012-06-17 16:18 . 2012-06-17 16:18 -------- d-----w- c:\users\Zbyněk\AppData\Local\{437E96FB-7F75-4BA5-87D9-77B47B95C5A6}
2012-06-17 07:46 . 2012-06-17 07:46 -------- d-----w- c:\users\Zbyněk\AppData\Local\Macromedia
2012-06-15 08:29 . 2012-06-15 08:29 -------- d-----w- c:\users\Zbyněk\AppData\Local\{169B9964-8E80-4EF2-8EA1-10673E00C3C0}
2012-06-14 04:53 . 2012-04-28 03:17 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-14 04:53 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\system32\msi.dll
2012-06-14 04:53 . 2012-05-15 01:05 2343936 ----a-w- c:\windows\system32\win32k.sys
2012-06-14 04:53 . 2012-04-26 04:45 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-06-14 04:53 . 2012-04-26 04:45 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-06-14 04:53 . 2012-04-26 04:41 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-14 04:53 . 2012-05-01 04:44 164352 ----a-w- c:\windows\system32\profsvc.dll
2012-06-14 04:53 . 2012-04-24 04:36 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-14 04:53 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\system32\crypt32.dll
2012-06-14 04:53 . 2012-04-24 04:36 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-14 04:04 . 2012-06-14 04:04 -------- d-----w- c:\users\Zbyněk\AppData\Local\{EE8C82C0-38C8-4E2B-92C1-3E7D172419A6}
2012-06-14 04:03 . 2012-06-14 04:04 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8E815DD7-FBB0-458C-A847-F4FF9D0A8155}
2012-06-13 20:06 . 2012-06-13 20:06 -------- d-----w- c:\users\Zbyněk\AppData\Local\{47B0937E-AED0-4827-A781-EE6B382C2244}
2012-06-13 05:15 . 2012-06-13 05:15 -------- d-----w- c:\users\Zbyněk\AppData\Local\{0DDE7980-707F-4204-8029-31A52A712C54}
2012-06-13 05:15 . 2012-06-13 05:15 -------- d-----w- c:\users\Zbyněk\AppData\Local\{A00520B7-6A0F-4605-B5BE-8B21B4FEE2EE}
2012-06-12 10:31 . 2012-06-12 10:31 -------- d-----w- c:\users\Zbyněk\AppData\Local\{04053703-0CC6-456E-85E0-CB68A0D55664}
2012-06-12 10:31 . 2012-06-12 10:31 -------- d-----w- c:\users\Zbyněk\AppData\Local\{95DE0F38-DE5C-46C9-89E5-C1766C06BBAD}
2012-06-11 08:09 . 2012-06-11 08:09 -------- d-----w- c:\users\Zbyněk\AppData\Local\{7861CCF0-2FEE-4DB1-B036-05955B43E4C4}
2012-06-11 08:09 . 2012-06-11 08:09 -------- d-----w- c:\users\Zbyněk\AppData\Local\{F03B8DDB-74E5-45FC-B934-3FC9D7A4E72E}
2012-06-10 18:25 . 2012-06-10 18:26 -------- d-----w- c:\users\Zbyněk\AppData\Local\{8D44C865-9A75-4543-9BF3-31E50D710245}
2012-06-10 18:25 . 2012-06-10 18:25 -------- d-----w- c:\users\Zbyněk\AppData\Local\{AFD26AB6-9B85-4F44-ABAC-6F27A6AE2DC3}
2012-06-09 20:00 . 2012-06-09 20:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{FA1238AF-723D-4FE4-8B2B-76EAD0C7F402}
2012-06-09 20:00 . 2012-06-09 20:00 -------- d-----w- c:\users\Zbyněk\AppData\Local\{44DF5E7A-D542-4766-8B31-ABCAA2D8BBE7}
2012-06-09 07:13 . 2012-06-09 07:13 -------- d-----w- c:\users\Zbyněk\AppData\Local\{110A0EAC-5D21-4B2B-84EE-01558EA27A22}
2012-06-09 07:13 . 2012-06-09 07:13 -------- d-----w- c:\users\Zbyněk\AppData\Local\{E4DF1BB1-1B06-4F5C-B661-67B624FC7E06}
2012-06-08 09:01 . 2012-06-08 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{96A58D79-12FE-4428-A3F1-4003C6E1B257}
2012-06-08 09:01 . 2012-06-08 09:01 -------- d-----w- c:\users\Zbyněk\AppData\Local\{64FC1883-A02D-4858-8066-41B6D7B00D0A}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-14 22:19 . 2012-07-07 21:00 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"ALLUpdate"="c:\program files\OpenSubtitlesPlayer\ALLUpdate.exe" [2011-02-26 1022464]
"Facebook Update"="c:\users\Zbyněk\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-09-30 137536]
"Akamai NetSession Interface"="c:\users\Zbyněk\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
"NokiaSuite.exe"="c:\program files\Nokia\Nokia Suite\NokiaSuite.exe" [2012-01-10 1083264]
"InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-10-11 1179648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-24 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"YouCam Mirror Tray icon"="c:\program files\CyberLink\YouCam\YouCamTray.exe" [2009-06-11 162912]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"Print2PDF Print Monitor"="c:\program files\Software602\Print2PDF\Print2PDF.exe" [2011-04-12 222776]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2011-06-15 273544]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Clearblue.lnk - c:\windows\Installer\{D99F7568-803E-4C13-80DD-9403CD34F5F3}\_F015326B9D6121FF10D37F.exe [2011-7-13 370070]
Philips GoGear VIBE Device Manager.lnk - c:\philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe [2011-5-6 1611152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 602XML Updater;602Updater;c:\program files\Common Files\soft602\602updsvc\602updsvc.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S3 AsAudioDevice_349;AsAudioDevice_349;c:\windows\system32\drivers\AsAudioDevice_349.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2012-07-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-06 11:10]
.
2012-07-08 c:\windows\Tasks\FinalTorrent Update Checker.job
- c:\program files\FinalTorrent\FTCheckForUpdates.exe [2011-05-24 14:50]
.
2012-07-08 c:\windows\Tasks\FreeFileViewerUpdateChecker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2011-07-02 13:24]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-07 19:00]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-07 19:00]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.bigseekpro.com/howfytdl/{3B00801A-3 ... 6ECF289658}
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Zbyněk\AppData\Roaming\Mozilla\Firefox\Profiles\rvnxzunm.default-1341695351180\
FF - prefs.js: browser.startup.homepage - http://www.seznam.cz
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe
AddRemove-Complitly_is1 - c:\program files\Complitly\unins000.exe
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_80c2ffa.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-07-08 10:15:01
ComboFix-quarantined-files.txt 2012-07-08 08:15
.
Před spuštěním: Volných bajtů: 169 411 903 488
Po spuštění: Volných bajtů: 169 315 930 112
.
- - End Of File - - 1A5F44689B28FCF7856A2701F61B139E