Výrazné zpomalení internetu
Napsal: 25 srp 2013 11:01
Dobrý den, poslední dobou se mi výrazně zpomalil internet. Můj poskytovatel je o2, internet mám 7 mb... dříve mi běhal kolem 500 kb ale teď 20-50 kb. Mám podezření na vir. Antivirus jsem měl eset ale potom co jsem zjistil že eset může zpomalovat internet tak jsem přešel na avg a z avg na nic... bohužel problémy stále přetrvávají... Posílám log z combofixu
ComboFix 13-08-20.01 - OEM 25.08.2013 11:37:58.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4055.2784 [GMT 2:00]
Spuštěný z: c:\users\OEM\Downloads\ComboFix.exe
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-25 do 2013-08-25 )))))))))))))))))))))))))))))))
.
.
2013-08-25 09:44 . 2013-08-25 09:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-25 09:44 . 2013-08-25 09:44 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-08-23 13:42 . 2012-06-01 05:36 192000 ----a-w- c:\windows\system32\iisRtl.dll
2013-08-23 13:42 . 2012-06-01 05:39 14848 ----a-w- c:\windows\system32\wamregps.dll
2013-08-23 13:42 . 2012-06-01 05:36 11264 ----a-w- c:\windows\system32\iisrstap.dll
2013-08-23 13:42 . 2012-06-01 05:35 60928 ----a-w- c:\windows\system32\ahadmin.dll
2013-08-23 13:42 . 2012-06-01 05:34 55296 ----a-w- c:\windows\system32\admwprox.dll
2013-08-23 13:42 . 2012-06-01 05:33 16896 ----a-w- c:\windows\system32\iisreset.exe
2013-08-23 13:42 . 2012-06-01 04:40 10752 ----a-w- c:\windows\SysWow64\wamregps.dll
2013-08-23 13:42 . 2012-06-01 04:37 8192 ----a-w- c:\windows\SysWow64\iisrstap.dll
2013-08-23 13:42 . 2012-06-01 04:37 154624 ----a-w- c:\windows\SysWow64\iisRtl.dll
2013-08-23 13:42 . 2012-06-01 04:35 26624 ----a-w- c:\windows\SysWow64\ahadmin.dll
2013-08-23 13:42 . 2012-06-01 04:35 50688 ----a-w- c:\windows\SysWow64\admwprox.dll
2013-08-23 13:42 . 2012-06-01 04:34 15360 ----a-w- c:\windows\SysWow64\iisreset.exe
2013-08-23 13:17 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EDA208F6-AF8B-4534-B661-51392E291C07}\mpengine.dll
2013-08-23 08:35 . 2013-08-23 08:35 -------- d-----w- c:\users\OEM\AppData\Local\Avg2013
2013-08-22 17:17 . 2013-08-25 09:46 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- c:\windows\SysWow64\BestPractices
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- c:\windows\system32\msmq
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- c:\windows\system32\BestPractices
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- C:\inetpub
2013-08-22 10:35 . 2013-08-24 14:57 -------- d-----w- c:\program files (x86)\AVG Secure Search
2013-08-22 09:50 . 2013-08-22 09:50 -------- d-----w- c:\users\OEM\AppData\Local\AVG Secure Search
2013-08-22 09:49 . 2013-08-24 14:57 45856 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2013-08-22 09:49 . 2013-08-22 09:49 -------- d-----w- c:\programdata\AVG Secure Search
2013-08-22 09:49 . 2013-08-22 09:49 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2013-08-22 09:45 . 2013-08-23 08:35 -------- d-----w- c:\programdata\MFAData
2013-08-22 09:45 . 2013-08-22 09:45 -------- d-----w- c:\users\OEM\AppData\Local\MFAData
2013-08-22 09:29 . 2013-08-22 09:29 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-08-22 09:29 . 2013-08-22 09:29 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-22 09:29 . 2013-08-22 09:29 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-08-22 09:29 . 2013-08-22 09:29 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-08-22 09:29 . 2013-08-22 09:29 3913664 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-08-22 09:29 . 2013-08-22 09:29 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-08-22 09:29 . 2013-08-22 09:29 243712 ----a-w- c:\windows\system32\wow64.dll
2013-08-22 09:29 . 2013-08-22 09:29 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-08-22 09:29 . 2013-08-22 09:29 1732032 ----a-w- c:\windows\system32\ntdll.dll
2013-08-22 09:29 . 2013-08-22 09:29 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-08-22 09:29 . 2013-08-22 09:29 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2013-08-22 08:19 . 2013-08-22 08:19 -------- d-----w- c:\program files (x86)\IObit Apps Toolbar
2013-08-22 08:19 . 2013-08-22 08:19 -------- d-----w- c:\program files (x86)\Common Files\Spigot
2013-08-22 08:19 . 2013-08-22 08:19 -------- d-----w- c:\program files (x86)\Application Updater
2013-08-18 06:44 . 2013-08-24 18:10 -------- d-----w- c:\users\OEM\AppData\Roaming\BitTorrent
2013-08-17 11:55 . 2013-08-17 11:55 -------- d-----w- c:\users\OEM\AppData\Local\Locktime
2013-08-17 11:52 . 2013-08-17 11:52 -------- d-----w- c:\program files\NetLimiter 3
2013-08-17 11:52 . 2013-08-17 11:52 -------- d-----w- c:\programdata\Locktime
2013-08-17 11:52 . 2013-08-17 11:53 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
2013-08-17 11:24 . 2013-08-17 11:24 -------- d-----w- c:\program files (x86)\NirSoft
2013-08-16 11:49 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-08-16 11:49 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-08-16 11:49 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-16 11:49 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-16 11:49 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-08-16 11:49 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-08-16 11:49 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-08-16 11:49 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-08-16 11:47 . 2013-07-19 01:58 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-16 11:47 . 2013-07-19 01:41 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-08-16 11:47 . 2013-07-25 09:25 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-16 11:47 . 2013-07-25 08:57 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-08-16 11:47 . 2013-07-09 05:51 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-16 11:47 . 2013-07-09 04:52 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-08-16 11:47 . 2013-06-15 04:32 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-16 11:47 . 2013-07-06 06:03 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-15 09:43 . 2013-08-15 09:43 -------- d-----w- c:\users\OEM\AppData\Local\PAYDAY
2013-08-15 09:38 . 2013-08-15 09:38 -------- d-----w- c:\program files (x86)\Black_Box
2013-08-15 09:38 . 2013-08-15 09:38 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-15 07:58 . 2013-08-15 08:08 -------- d-----w- c:\users\OEM\AppData\Roaming\TP-LINK
2013-08-15 07:58 . 2013-08-15 07:58 -------- d-----w- c:\program files (x86)\TP-LINK
2013-08-15 07:57 . 2012-10-18 13:04 1930240 ----a-w- c:\windows\system32\drivers\athurx.sys
2013-08-15 07:57 . 2012-10-18 13:04 1930240 ------w- c:\windows\system32\athurx.sys
2013-08-15 07:56 . 2013-08-15 07:58 -------- d-----w- c:\programdata\TP-LINK
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-24 18:01 . 2012-12-18 16:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-08-24 18:01 . 2012-11-09 16:08 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-08-24 18:00 . 2012-11-09 16:08 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-08-22 09:29 . 2013-08-22 09:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-08-16 17:23 . 2012-11-07 19:53 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-07-19 07:32 . 2013-07-19 07:32 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-07-02 07:52 . 2013-06-15 15:55 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2013-07-02 07:52 . 2013-07-02 07:52 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2013-06-21 07:04 . 2013-06-21 07:04 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2013-06-19 08:27 . 2012-11-09 16:08 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-06-16 18:40 . 2013-06-16 12:10 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2013-06-16 18:40 . 2013-06-16 12:10 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2013-06-16 18:40 . 2013-06-16 12:10 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2013-06-16 18:40 . 2013-06-16 12:10 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2013-06-15 15:55 . 2013-06-15 15:55 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2013-06-12 12:20 . 2012-11-07 18:35 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 12:20 . 2012-11-07 18:35 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 12:20 . 2013-06-12 12:20 9089416 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-06-12 07:48 . 2013-06-12 07:48 32688 ----a-w- c:\windows\system32\drivers\nlndis.sys
2013-06-05 03:34 . 2013-07-10 14:56 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 06:00 . 2013-07-10 14:56 624128 ----a-w- c:\windows\system32\qedit.dll
2013-06-04 04:53 . 2013-07-10 14:56 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2013-05-29 07:55 . 2013-05-29 07:55 707354 ----a-w- c:\windows\unins000.exe
2005-08-26 12:20 . 2013-03-10 07:07 177664 ----a-w- c:\program files (x86)\Version Changer fr.exe
2002-08-28 11:41 . 2013-03-10 07:04 11376 ----a-r- c:\program files (x86)\SECDRV.SYS
2002-08-28 09:22 . 2013-03-10 07:04 40960 ----a-r- c:\program files (x86)\DrvMgt.dll
2002-08-20 02:09 . 2013-03-10 07:04 3237078 ----a-r- c:\program files (x86)\Game.exe
2002-08-03 14:51 . 2013-03-10 07:04 851968 ----a-r- c:\program files (x86)\LS3DF.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll" [2013-08-08 1356096]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
2013-08-08 17:33 1356096 ----a-w- c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll" [2013-08-08 1356096]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-04-19 18678376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2013-08-24 2314416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 ALSysIO;ALSysIO; [x]
R3 MailList Controller;MailList Controller;c:\program files (x86)\arclab\maillist controller\amlcSVC.exe;c:\program files (x86)\arclab\maillist controller\amlcSVC.exe [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 nltdi;nltdi;c:\program files\NetLimiter 3\nltdi.sys;c:\program files\NetLimiter 3\nltdi.sys [x]
S2 ACT2_Service;Ashampoo Core Tuner 2 Service;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe [x]
S2 ACT2PM;Ashampoo CoreTuner 2 ProcessMonitor Driver;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2ProcessMonitor64.sys;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2ProcessMonitor64.sys [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-22 13:20 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3395566686-3764996113-1460129602-1000Core.job
- c:\users\OEM\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-25 16:33]
.
2013-07-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3395566686-3764996113-1460129602-1000UA.job
- c:\users\OEM\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-25 16:33]
.
2013-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ce7ba38e296e4d.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-23 06:08]
.
2013-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA1ce0d1086a5840.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-23 06:08]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2010-11-20 247808]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.co.uk/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
TCP: DhcpNameServer = 10.0.0.138
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll
FF - ProfilePath - c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=
FF - ExtSQL: 2013-07-03 09:27; searchy@searchy; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\searchy@searchy.xpi
FF - ExtSQL: 2013-07-11 12:30; client@anonymox.net; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\client@anonymox.net.xpi
FF - ExtSQL: 2013-07-13 11:07; {96f454ea-9d38-474f-b504-56193e00c1a5}; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}
FF - ExtSQL: 2013-07-19 09:36; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF - ExtSQL: 2013-08-22 10:19; iobitapps@mybrowserbar.com; c:\program files (x86)\IObit Apps Toolbar\FF
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: extentions.webcake.defaultEnableAppsList - layers,brain/features,newOffers/wc
FF - user.js: extentions.webcake.installId - f80230d2-fe15-4843-88d5-42cbed43f724
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3395566686-3764996113-1460129602-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:ee,5a,20,72,ad,ac,ee,c1,3c,16,2d,34,2c,e8,a4,66,91,91,03,b3,29,
90,c2,e2,e3,ef,9a,c7,88,87,a3,c2,c7,e4,8f,cd,34,dd,e1,fb,88,9e,67,34,e0,33,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
.
**************************************************************************
.
Celkový čas: 2013-08-25 11:50:02 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-08-25 09:50
ComboFix2.txt 2013-08-22 08:10
.
Před spuštěním: Volných bajtů: 628 340 953 088
Po spuštění: Volných bajtů: 633 605 484 544
.
- - End Of File - - BFDC7C100E7426E17A3A5D7D455B42C9
A36C5E4F47E84449FF07ED3517B43A31
ComboFix 13-08-20.01 - OEM 25.08.2013 11:37:58.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4055.2784 [GMT 2:00]
Spuštěný z: c:\users\OEM\Downloads\ComboFix.exe
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-25 do 2013-08-25 )))))))))))))))))))))))))))))))
.
.
2013-08-25 09:44 . 2013-08-25 09:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-25 09:44 . 2013-08-25 09:44 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-08-23 13:42 . 2012-06-01 05:36 192000 ----a-w- c:\windows\system32\iisRtl.dll
2013-08-23 13:42 . 2012-06-01 05:39 14848 ----a-w- c:\windows\system32\wamregps.dll
2013-08-23 13:42 . 2012-06-01 05:36 11264 ----a-w- c:\windows\system32\iisrstap.dll
2013-08-23 13:42 . 2012-06-01 05:35 60928 ----a-w- c:\windows\system32\ahadmin.dll
2013-08-23 13:42 . 2012-06-01 05:34 55296 ----a-w- c:\windows\system32\admwprox.dll
2013-08-23 13:42 . 2012-06-01 05:33 16896 ----a-w- c:\windows\system32\iisreset.exe
2013-08-23 13:42 . 2012-06-01 04:40 10752 ----a-w- c:\windows\SysWow64\wamregps.dll
2013-08-23 13:42 . 2012-06-01 04:37 8192 ----a-w- c:\windows\SysWow64\iisrstap.dll
2013-08-23 13:42 . 2012-06-01 04:37 154624 ----a-w- c:\windows\SysWow64\iisRtl.dll
2013-08-23 13:42 . 2012-06-01 04:35 26624 ----a-w- c:\windows\SysWow64\ahadmin.dll
2013-08-23 13:42 . 2012-06-01 04:35 50688 ----a-w- c:\windows\SysWow64\admwprox.dll
2013-08-23 13:42 . 2012-06-01 04:34 15360 ----a-w- c:\windows\SysWow64\iisreset.exe
2013-08-23 13:17 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EDA208F6-AF8B-4534-B661-51392E291C07}\mpengine.dll
2013-08-23 08:35 . 2013-08-23 08:35 -------- d-----w- c:\users\OEM\AppData\Local\Avg2013
2013-08-22 17:17 . 2013-08-25 09:46 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- c:\windows\SysWow64\BestPractices
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- c:\windows\system32\msmq
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- c:\windows\system32\BestPractices
2013-08-22 17:16 . 2013-08-22 17:16 -------- d-----w- C:\inetpub
2013-08-22 10:35 . 2013-08-24 14:57 -------- d-----w- c:\program files (x86)\AVG Secure Search
2013-08-22 09:50 . 2013-08-22 09:50 -------- d-----w- c:\users\OEM\AppData\Local\AVG Secure Search
2013-08-22 09:49 . 2013-08-24 14:57 45856 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2013-08-22 09:49 . 2013-08-22 09:49 -------- d-----w- c:\programdata\AVG Secure Search
2013-08-22 09:49 . 2013-08-22 09:49 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2013-08-22 09:45 . 2013-08-23 08:35 -------- d-----w- c:\programdata\MFAData
2013-08-22 09:45 . 2013-08-22 09:45 -------- d-----w- c:\users\OEM\AppData\Local\MFAData
2013-08-22 09:29 . 2013-08-22 09:29 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-08-22 09:29 . 2013-08-22 09:29 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-22 09:29 . 2013-08-22 09:29 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-08-22 09:29 . 2013-08-22 09:29 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-08-22 09:29 . 2013-08-22 09:29 3913664 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-08-22 09:29 . 2013-08-22 09:29 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-08-22 09:29 . 2013-08-22 09:29 243712 ----a-w- c:\windows\system32\wow64.dll
2013-08-22 09:29 . 2013-08-22 09:29 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-08-22 09:29 . 2013-08-22 09:29 1732032 ----a-w- c:\windows\system32\ntdll.dll
2013-08-22 09:29 . 2013-08-22 09:29 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-08-22 09:29 . 2013-08-22 09:29 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2013-08-22 08:19 . 2013-08-22 08:19 -------- d-----w- c:\program files (x86)\IObit Apps Toolbar
2013-08-22 08:19 . 2013-08-22 08:19 -------- d-----w- c:\program files (x86)\Common Files\Spigot
2013-08-22 08:19 . 2013-08-22 08:19 -------- d-----w- c:\program files (x86)\Application Updater
2013-08-18 06:44 . 2013-08-24 18:10 -------- d-----w- c:\users\OEM\AppData\Roaming\BitTorrent
2013-08-17 11:55 . 2013-08-17 11:55 -------- d-----w- c:\users\OEM\AppData\Local\Locktime
2013-08-17 11:52 . 2013-08-17 11:52 -------- d-----w- c:\program files\NetLimiter 3
2013-08-17 11:52 . 2013-08-17 11:52 -------- d-----w- c:\programdata\Locktime
2013-08-17 11:52 . 2013-08-17 11:53 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
2013-08-17 11:24 . 2013-08-17 11:24 -------- d-----w- c:\program files (x86)\NirSoft
2013-08-16 11:49 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-08-16 11:49 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-08-16 11:49 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-16 11:49 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-16 11:49 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-08-16 11:49 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-08-16 11:49 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-08-16 11:49 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-08-16 11:47 . 2013-07-19 01:58 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-16 11:47 . 2013-07-19 01:41 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-08-16 11:47 . 2013-07-25 09:25 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-16 11:47 . 2013-07-25 08:57 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-08-16 11:47 . 2013-07-09 05:51 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-16 11:47 . 2013-07-09 04:52 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-08-16 11:47 . 2013-06-15 04:32 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-16 11:47 . 2013-07-06 06:03 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-15 09:43 . 2013-08-15 09:43 -------- d-----w- c:\users\OEM\AppData\Local\PAYDAY
2013-08-15 09:38 . 2013-08-15 09:38 -------- d-----w- c:\program files (x86)\Black_Box
2013-08-15 09:38 . 2013-08-15 09:38 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-15 07:58 . 2013-08-15 08:08 -------- d-----w- c:\users\OEM\AppData\Roaming\TP-LINK
2013-08-15 07:58 . 2013-08-15 07:58 -------- d-----w- c:\program files (x86)\TP-LINK
2013-08-15 07:57 . 2012-10-18 13:04 1930240 ----a-w- c:\windows\system32\drivers\athurx.sys
2013-08-15 07:57 . 2012-10-18 13:04 1930240 ------w- c:\windows\system32\athurx.sys
2013-08-15 07:56 . 2013-08-15 07:58 -------- d-----w- c:\programdata\TP-LINK
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-24 18:01 . 2012-12-18 16:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-08-24 18:01 . 2012-11-09 16:08 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-08-24 18:00 . 2012-11-09 16:08 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-08-22 09:29 . 2013-08-22 09:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-08-16 17:23 . 2012-11-07 19:53 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-07-19 07:32 . 2013-07-19 07:32 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-07-02 07:52 . 2013-06-15 15:55 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2013-07-02 07:52 . 2013-07-02 07:52 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2013-06-21 07:04 . 2013-06-21 07:04 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2013-06-19 08:27 . 2012-11-09 16:08 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-06-16 18:40 . 2013-06-16 12:10 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2013-06-16 18:40 . 2013-06-16 12:10 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2013-06-16 18:40 . 2013-06-16 12:10 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2013-06-16 18:40 . 2013-06-16 12:10 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2013-06-15 15:55 . 2013-06-15 15:55 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2013-06-12 12:20 . 2012-11-07 18:35 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 12:20 . 2012-11-07 18:35 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 12:20 . 2013-06-12 12:20 9089416 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-06-12 07:48 . 2013-06-12 07:48 32688 ----a-w- c:\windows\system32\drivers\nlndis.sys
2013-06-05 03:34 . 2013-07-10 14:56 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 06:00 . 2013-07-10 14:56 624128 ----a-w- c:\windows\system32\qedit.dll
2013-06-04 04:53 . 2013-07-10 14:56 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2013-05-29 07:55 . 2013-05-29 07:55 707354 ----a-w- c:\windows\unins000.exe
2005-08-26 12:20 . 2013-03-10 07:07 177664 ----a-w- c:\program files (x86)\Version Changer fr.exe
2002-08-28 11:41 . 2013-03-10 07:04 11376 ----a-r- c:\program files (x86)\SECDRV.SYS
2002-08-28 09:22 . 2013-03-10 07:04 40960 ----a-r- c:\program files (x86)\DrvMgt.dll
2002-08-20 02:09 . 2013-03-10 07:04 3237078 ----a-r- c:\program files (x86)\Game.exe
2002-08-03 14:51 . 2013-03-10 07:04 851968 ----a-r- c:\program files (x86)\LS3DF.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll" [2013-08-08 1356096]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
2013-08-08 17:33 1356096 ----a-w- c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll" [2013-08-08 1356096]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-04-19 18678376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2013-08-24 2314416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 ALSysIO;ALSysIO; [x]
R3 MailList Controller;MailList Controller;c:\program files (x86)\arclab\maillist controller\amlcSVC.exe;c:\program files (x86)\arclab\maillist controller\amlcSVC.exe [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 nltdi;nltdi;c:\program files\NetLimiter 3\nltdi.sys;c:\program files\NetLimiter 3\nltdi.sys [x]
S2 ACT2_Service;Ashampoo Core Tuner 2 Service;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe [x]
S2 ACT2PM;Ashampoo CoreTuner 2 ProcessMonitor Driver;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2ProcessMonitor64.sys;c:\program files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2ProcessMonitor64.sys [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys;c:\windows\SYSNATIVE\DRIVERS\nlndis.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-22 13:20 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3395566686-3764996113-1460129602-1000Core.job
- c:\users\OEM\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-25 16:33]
.
2013-07-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3395566686-3764996113-1460129602-1000UA.job
- c:\users\OEM\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-25 16:33]
.
2013-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ce7ba38e296e4d.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-23 06:08]
.
2013-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA1ce0d1086a5840.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-23 06:08]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2010-11-20 247808]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.co.uk/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
TCP: DhcpNameServer = 10.0.0.138
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll
FF - ProfilePath - c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=
FF - ExtSQL: 2013-07-03 09:27; searchy@searchy; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\searchy@searchy.xpi
FF - ExtSQL: 2013-07-11 12:30; client@anonymox.net; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\client@anonymox.net.xpi
FF - ExtSQL: 2013-07-13 11:07; {96f454ea-9d38-474f-b504-56193e00c1a5}; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}
FF - ExtSQL: 2013-07-19 09:36; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\i11ju112.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF - ExtSQL: 2013-08-22 10:19; iobitapps@mybrowserbar.com; c:\program files (x86)\IObit Apps Toolbar\FF
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: extentions.webcake.defaultEnableAppsList - layers,brain/features,newOffers/wc
FF - user.js: extentions.webcake.installId - f80230d2-fe15-4843-88d5-42cbed43f724
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3395566686-3764996113-1460129602-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:ee,5a,20,72,ad,ac,ee,c1,3c,16,2d,34,2c,e8,a4,66,91,91,03,b3,29,
90,c2,e2,e3,ef,9a,c7,88,87,a3,c2,c7,e4,8f,cd,34,dd,e1,fb,88,9e,67,34,e0,33,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
.
**************************************************************************
.
Celkový čas: 2013-08-25 11:50:02 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-08-25 09:50
ComboFix2.txt 2013-08-22 08:10
.
Před spuštěním: Volných bajtů: 628 340 953 088
Po spuštění: Volných bajtů: 633 605 484 544
.
- - End Of File - - BFDC7C100E7426E17A3A5D7D455B42C9
A36C5E4F47E84449FF07ED3517B43A31