Tu je log:
ComboFix 13-02-24.01 - Thinkpad . 02. 2013 12:46:46.1.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1029.18.1913.978 [GMT 1:00]
Running from: c:\users\Thinkpad\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\AdbWinApi.dll
c:\windows\system32\AdbWinUsbApi.dll
c:\windows\system32\Config.ini
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\UA000079.DLL
G:\setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-01-26 to 2013-02-26 )))))))))))))))))))))))))))))))
.
.
2013-02-26 12:05 . 2013-02-26 12:05 -------- d-----w- c:\users\Thinkpad\AppData\Local\temp
2013-02-26 12:05 . 2013-02-26 12:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-26 09:49 . 2013-02-26 09:49 -------- d-----w- c:\users\Thinkpad\AppData\Roaming\Malwarebytes
2013-02-26 09:49 . 2013-02-26 09:49 -------- d-----w- c:\programdata\Malwarebytes
2013-02-26 09:49 . 2013-02-26 09:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-26 09:49 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-26 09:49 . 2013-02-26 09:49 -------- d-----w- c:\users\Thinkpad\AppData\Local\Programs
2013-02-26 09:41 . 2013-02-26 11:04 -------- d-----w- c:\program files\trend micro
2013-02-26 09:41 . 2013-02-26 09:41 -------- d-----w- C:\rsit
2013-02-19 22:58 . 2013-02-19 22:58 -------- d-----w- c:\users\Thinkpad\AppData\Roaming\HD Tune Pro
2013-02-19 17:39 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-19 17:39 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-19 17:39 . 2012-10-15 16:59 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-02-19 17:39 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-19 17:39 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-19 17:39 . 2012-10-30 22:51 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-02-19 17:39 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2013-02-19 17:39 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-02-19 17:15 . 2013-02-19 17:15 -------- d--h--w- c:\windows\PIF
2013-02-19 15:50 . 2012-12-17 05:43 33616 ----a-w- c:\windows\system32\drivers\gfiark.sys
2013-02-19 15:02 . 2013-02-19 15:02 -------- d-----w- c:\programdata\Ad-Aware Antivirus
2013-02-19 14:58 . 2013-02-19 14:58 -------- d-----w- c:\users\Thinkpad\AppData\Local\adawarebp
2013-02-19 14:58 . 2013-02-19 14:58 -------- d-----w- c:\programdata\Ad-Aware Browsing Protection
2013-02-19 14:58 . 2013-02-19 14:58 -------- d-----w- c:\program files\Toolbar Cleaner
2013-02-19 14:57 . 2013-02-19 15:50 -------- d-----w- c:\program files\Ad-Aware Antivirus
2013-02-19 14:57 . 2013-02-19 14:57 -------- d-----w- c:\windows\system32\drivers\VDD
2013-02-19 14:57 . 2013-02-19 14:57 -------- d-----w- c:\programdata\Lavasoft
2013-02-19 14:57 . 2013-02-19 14:57 -------- d-----w- c:\programdata\Downloaded Installations
2013-02-19 14:53 . 2013-02-19 14:53 13560 ----a-w- c:\windows\system32\drivers\gfibto.sys
2013-02-19 14:53 . 2013-02-26 11:34 -------- d-----w- c:\users\Thinkpad\AppData\Roaming\Ad-Aware Antivirus
2013-02-19 14:26 . 2013-02-19 14:26 -------- d-----w- c:\program files\CCleaner
2013-02-17 19:47 . 2013-02-18 20:56 -------- d-----w- c:\program files\Seznam.cz
2013-02-17 19:43 . 2013-02-18 20:59 -------- d-----w- c:\users\Thinkpad\AppData\Roaming\Seznam.cz
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-10 08:25 . 2013-01-10 08:25 46056 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys
2012-12-12 12:49 . 2012-04-26 20:15 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-12 12:49 . 2011-07-30 10:42 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-08 174104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-08 151064]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-02-25 8522272]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2009-08-17 12:27 100104 ----a-w- c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R2 5689;5689;d:\temp\5689.sys [x]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [x]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [x]
R3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [x]
S2 SBAMSvc;Ad-Aware;c:\program files\Ad-Aware Antivirus\SBAMSvc.exe [x]
S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [x]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [x]
S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [x]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.sk/
mStart Page = hxxp://
www.google.com
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.102.1 192.168.102.253
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(656)
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
.
Completion time: 2013-02-26 13:08:24
ComboFix-quarantined-files.txt 2013-02-26 12:08
.
Pre-Run: Volných bajtů: 28 477 562 880
Post-Run: Volných bajtů: 28 489 039 872
.
- - End Of File - - A1CAF3149EC36B1417B988F57F752D4E