Kontrola logu
Napsal: 22 zář 2013 19:16
Omlouvám se pokud zde tento log nepatří.
ComboFix 13-09-22.01 - Pater 22.09.2013 19:35:47.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8053.5641 [GMT 2:00]
Spuštěný z: c:\users\Pater\Desktop\ComboFix.exe
AV: Doctor Web Anti-Virus *Disabled/Updated* {A8C161B2-600A-42FD-97E0-4C12952A9FEC}
FW: Dr.Web Firewall *Enabled* {54FD2F0C-F7E9-625E-7F1B-B80A587561A3}
SP: Doctor Web Anti-Virus *Disabled/Updated* {13A08056-4630-4D73-AD50-7760EEADD551}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Pater\AppData\Local\assembly\tmp
c:\users\Pater\chrome.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\image.jpg
c:\windows\TEMP\jna8131776503028649748.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-22 do 2013-09-22 )))))))))))))))))))))))))))))))
.
.
2013-09-22 17:53 . 2013-09-22 17:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-11 04:45 . 2013-07-31 13:09 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-09-11 04:24 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-09-08 11:43 . 2013-09-08 11:43 -------- d-----w- C:\perflogs
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-11 04:46 . 2010-11-12 23:23 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-08-02 01:48 . 2013-09-11 04:24 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 16:36 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 16:36 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 18:02 . 2013-07-19 18:02 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-19 18:02 . 2012-07-11 12:46 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-07-19 18:02 . 2010-12-25 17:18 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-07-19 01:58 . 2013-08-14 16:36 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 16:36 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 16:36 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 16:36 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 16:36 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 16:36 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-14 16:36 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-14 16:36 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 16:36 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 16:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 16:36 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-14 16:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-14 16:36 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-16 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SpIDerMail"="c:\program files (x86)\DrWeb\spiderml.exe" [2011-08-17 1591024]
"Dr.Web Firewall"="c:\program files (x86)\DrWeb\frwl_notify.exe" [2011-06-08 3822856]
"SpIDerAgent"="c:\program files (x86)\DrWeb\SpIDerAgent.exe" [2011-11-24 1476920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
R3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys;c:\windows\SYSNATIVE\DRIVERS\btwdpan.sys [x]
R3 cpuz134;cpuz134;c:\program files (x86)\CPUID\PC Wizard 2010\pcwiz_x64.sys;c:\program files (x86)\CPUID\PC Wizard 2010\pcwiz_x64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys;c:\windows\SYSNATIVE\Drivers\nx6000.sys [x]
R3 PcaSp60;Rawether NDIS 6.X SPR Protocol Driver;c:\windows\system32\DRIVERS\PcaSp60.sys;c:\windows\SYSNATIVE\DRIVERS\PcaSp60.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys;c:\windows\SYSNATIVE\DRIVERS\seehcri.sys [x]
R3 SpyEmrgAccess;Spy Emergency OnAccess Driver;c:\windows\system32\Drivers\spyemrg_access.sys;c:\windows\SYSNATIVE\Drivers\spyemrg_access.sys [x]
R3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver;c:\windows\system32\Drivers\spyemrg_guard.sys;c:\windows\SYSNATIVE\Drivers\spyemrg_guard.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 tmhidusb;Thrustmaster HID USB Driver;c:\windows\system32\DRIVERS\tmhidusb.sys;c:\windows\SYSNATIVE\DRIVERS\tmhidusb.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys;c:\windows\SYSNATIVE\drivers\dwprot.sys [x]
S0 SpiderG3;DrWeb file system scanner;c:\windows\system32\drivers\spiderg3.sys;c:\windows\SYSNATIVE\drivers\spiderg3.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 DRWEBAF;DrWEB Firewall Application Filter;c:\windows\system32\drivers\drwebaf.sys;c:\windows\SYSNATIVE\drivers\drwebaf.sys [x]
S1 SpyEmrg;Spy Emergency Driver;c:\windows\system32\Drivers\spyemrg.sys;c:\windows\SYSNATIVE\Drivers\spyemrg.sys [x]
S2 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine);c:\program files (x86)\Common Files\Doctor Web\Scanning Engine\dwengine.exe;c:\program files (x86)\Common Files\Doctor Web\Scanning Engine\dwengine.exe [x]
S2 DrWebFwSvc;Dr.Web Firewall Service;c:\program files (x86)\DrWeb\frwl_svc.exe;c:\program files (x86)\DrWeb\frwl_svc.exe [x]
S2 PS3 Media Server;PS3 Media Server;c:\program files (x86)\PS3 Media Server\win32\service\wrapper.exe;c:\program files (x86)\PS3 Media Server\win32\service\wrapper.exe [x]
S2 tmInstall;Thrustmaster Device Driver Installer;c:\program files\Thrustmaster\T500 RS Racing wheel\drivers\amd64\tmInstall.EXE;c:\program files\Thrustmaster\T500 RS Racing wheel\drivers\amd64\tmInstall.EXE [x]
S3 bbcap;bb_capture_driver;c:\windows\system32\DRIVERS\bbcap.sys;c:\windows\SYSNATIVE\DRIVERS\bbcap.sys [x]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 DrWebPF;DrWeb Packet Filter Driver;c:\windows\system32\DRIVERS\DrWebPF.sys;c:\windows\SYSNATIVE\DRIVERS\DrWebPF.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-05 c:\windows\Tasks\Dr.Web Daily scan.job
- c:\program files (x86)\DrWeb\drweb32w.exe [2011-07-12 09:04]
.
2013-09-22 c:\windows\Tasks\Dr.Web Update.job
- c:\program files (x86)\DrWeb\DrWebUpW.exe [2011-06-27 09:43]
.
2013-09-22 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-03-08 10:28]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-19 07:47]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-19 07:47]
.
2013-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4213455190-1121324071-2762663974-1000Core.job
- c:\users\Pater\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-27 06:11]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4213455190-1121324071-2762663974-1000UA.job
- c:\users\Pater\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-27 06:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = 127.0.0.1
IE: + Offline &Explorer: Download the link - file://c:\program files (x86)\Offline Explorer\Add_UrlO.htm
IE: + Offline E&xplorer: Download the current page - file://c:\program files (x86)\Offline Explorer\Add_AllO.htm
IE: Download All by ASUS Download - c:\program files (x86)\ASUS\RT-N16 Wireless Router Utilities\ASDownloadAll.htm
IE: Download using ASUS Download - c:\program files (x86)\ASUS\RT-N16 Wireless Router Utilities\ASDownload.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
LSP: c:\program files (x86)\DrWeb\drwebsp.dll
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojebanka.cz
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Pater\AppData\Roaming\Mozilla\Firefox\Profiles\mrkx3zot.default\
FF - ExtSQL: !HIDDEN! 2011-07-13 13:56; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-1771865536.www.idoklad.cz - c:\program files (x86)\Microsoft Silverlight\4.0.60310.0\Silverlight.Configuration.exe
AddRemove-2298590302.www.microsoft.com - c:\program files (x86)\Microsoft Silverlight\4.0.60310.0\Silverlight.Configuration.exe
.
.
"ImagePath"="system32\drivers\dwprot.sys"
"Name"="ImagePath"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-4213455190-1121324071-2762663974-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ED27F17A-65D3-59BB-C227-2061B01D39AE}*]
"maooenhihhfbpeaebomnmafilc"=hex:6f,61,6c,6d,66,6a,70,6b,69,6e,63,6a,66,61,67,
6c,63,61,67,63,6f,6e,65,66,68,6c,66,66,65,63,00,00
"abpopmpgchhplpilikilhpmbgbokhcfbkg"=hex:69,61,65,6f,6b,69,67,64,6b,66,66,61,
6f,65,6a,66,64,70,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="DCC2885B1D784C745984E13C63D57664B6F44391B696D6D43EB3DE1581C1171D66E99F61D4F6DD2DAA41B4D5C6572498EDB3AD4761B610EBF72CA1FC1FA5EFD6F56BEA85FDBEB62313C773511AD113019F3D8DAB5CD20C1CC744FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794A6A0AC4980AC79333C366C9A23FE34FCE727BD2E66FAC0FC18279F3479608FFD77D6CE099135A15B64468E004768035A4E64DA5FB66E8207233EA09E3028F9E1401011FCFE1D21D90922FD653A01F71D7904CA24238EBB2E5000E7EA20AE6BD9CFF16025B774E06B02EA001BA7DDF63E161AF46903753E9949921C4368B54859665CC68745BFF4EFC6CF1C25236963AFF6CB03D08F13E2655A33AB860ECC77CBE8BD90E09355F63F779820BD23DE28D1945663306B2601A2F2B2424777DCE50C5F1D4CA074630223D39F9DCF834FB3FC0909481098C47954A5F4544BF39E026DF8934F691FE7B858C3D16A7C009FF5FB13462730FD5B2FF12CF0198D32A3BFB2844EB193AAB6BE1250B31E193D09E58E16863B7F67A40769E1B40C3DC64C1716F70DCEAA16F73C7626D917ACBF18FB6618D281A584346D1945DFEBBBABD183C3EB27C6ED4227DD9E196FF6F373ACB62B45CC3DFA6970D055FCA6BA21BA3C05DD9D067E50731556199E322161A6FC17776B26738D8B10A2E5CED14236356B9EF8ECA59E7A55E357E7CFF33F170A90A35B7DA7EE9D4724D98827BD0C7B4013D89EE09612C7F38C1C026B9C3F6EB64566D814ABBE22DB8C716B9659662164383EC99F808946C0DADFCE53A4D1F3254B6B686721B345ED80E8B3CFA9668F8C385FEE771B78BA116DE2AF8C9B6CE834A6C472588C63E10388C1F8AB4761DF8B3FCEEF5AB3989D9E3AEAF3C123C7C0263288586904290C080383C6A6DEF36192D0A5A75B2C64988686C063C172E0A52298D06DC03324094BA0B71DDE30FC973DC47E62B4F91D8C4AEFAF37FBD1F97231DBBAF5AA58345001E8ED71198E9E3785457AE0C2A5478C4F650A1D082297B744D0E72F15490191C034B8AA3E63C1AB4D50BA58054CA9DFDE2BA23820D382BAAA9FFEC791EAF4AD05312EA458AA8F92D83968722321D18128D8D39DA06D47F31CC4A7635AB93D3AACE1E8309875F840CF27AFCC64E68EA2395978D78D0AB88FB3929097C7C44B80FC1B89905267303A3F153FF536F7F42589EC73E48B566BED6E2C6BEF592FD6FD9C872FFDFDB8AC3B17504BF4A8C05CA1F2A828B66396B7A4B08AEE6CB2315A6396A384A5B735A8B1ABFD0C4271C4E16331F2FEB2859FBBFABEFAD2FD999312985AC231A53D3D24BF3692BBCB691765E9E708643402DCD86E449ED58E79B80235BC8964137546E2BB525A"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-09-22 20:00:44 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-22 18:00
.
Před spuštěním: Volných bajtů: 127 887 958 016
Po spuštění: Volných bajtů: 127 512 272 896
.
- - End Of File - - CAC3C1E39AE4B9B626E39B6613934182
A36C5E4F47E84449FF07ED3517B43A31
ComboFix 13-09-22.01 - Pater 22.09.2013 19:35:47.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8053.5641 [GMT 2:00]
Spuštěný z: c:\users\Pater\Desktop\ComboFix.exe
AV: Doctor Web Anti-Virus *Disabled/Updated* {A8C161B2-600A-42FD-97E0-4C12952A9FEC}
FW: Dr.Web Firewall *Enabled* {54FD2F0C-F7E9-625E-7F1B-B80A587561A3}
SP: Doctor Web Anti-Virus *Disabled/Updated* {13A08056-4630-4D73-AD50-7760EEADD551}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Pater\AppData\Local\assembly\tmp
c:\users\Pater\chrome.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\image.jpg
c:\windows\TEMP\jna8131776503028649748.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-22 do 2013-09-22 )))))))))))))))))))))))))))))))
.
.
2013-09-22 17:53 . 2013-09-22 17:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-11 04:45 . 2013-07-31 13:09 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-09-11 04:24 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-09-08 11:43 . 2013-09-08 11:43 -------- d-----w- C:\perflogs
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-11 04:46 . 2010-11-12 23:23 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-08-02 01:48 . 2013-09-11 04:24 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 16:36 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 16:36 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 18:02 . 2013-07-19 18:02 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-19 18:02 . 2012-07-11 12:46 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-07-19 18:02 . 2010-12-25 17:18 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-07-19 01:58 . 2013-08-14 16:36 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 16:36 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 16:36 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 16:36 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 16:36 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 16:36 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-14 16:36 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-14 16:36 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 16:36 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 16:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 16:36 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-14 16:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-14 16:36 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-16 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SpIDerMail"="c:\program files (x86)\DrWeb\spiderml.exe" [2011-08-17 1591024]
"Dr.Web Firewall"="c:\program files (x86)\DrWeb\frwl_notify.exe" [2011-06-08 3822856]
"SpIDerAgent"="c:\program files (x86)\DrWeb\SpIDerAgent.exe" [2011-11-24 1476920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
R3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys;c:\windows\SYSNATIVE\DRIVERS\btwdpan.sys [x]
R3 cpuz134;cpuz134;c:\program files (x86)\CPUID\PC Wizard 2010\pcwiz_x64.sys;c:\program files (x86)\CPUID\PC Wizard 2010\pcwiz_x64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys;c:\windows\SYSNATIVE\Drivers\nx6000.sys [x]
R3 PcaSp60;Rawether NDIS 6.X SPR Protocol Driver;c:\windows\system32\DRIVERS\PcaSp60.sys;c:\windows\SYSNATIVE\DRIVERS\PcaSp60.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys;c:\windows\SYSNATIVE\DRIVERS\seehcri.sys [x]
R3 SpyEmrgAccess;Spy Emergency OnAccess Driver;c:\windows\system32\Drivers\spyemrg_access.sys;c:\windows\SYSNATIVE\Drivers\spyemrg_access.sys [x]
R3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver;c:\windows\system32\Drivers\spyemrg_guard.sys;c:\windows\SYSNATIVE\Drivers\spyemrg_guard.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 tmhidusb;Thrustmaster HID USB Driver;c:\windows\system32\DRIVERS\tmhidusb.sys;c:\windows\SYSNATIVE\DRIVERS\tmhidusb.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys;c:\windows\SYSNATIVE\drivers\dwprot.sys [x]
S0 SpiderG3;DrWeb file system scanner;c:\windows\system32\drivers\spiderg3.sys;c:\windows\SYSNATIVE\drivers\spiderg3.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 DRWEBAF;DrWEB Firewall Application Filter;c:\windows\system32\drivers\drwebaf.sys;c:\windows\SYSNATIVE\drivers\drwebaf.sys [x]
S1 SpyEmrg;Spy Emergency Driver;c:\windows\system32\Drivers\spyemrg.sys;c:\windows\SYSNATIVE\Drivers\spyemrg.sys [x]
S2 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine);c:\program files (x86)\Common Files\Doctor Web\Scanning Engine\dwengine.exe;c:\program files (x86)\Common Files\Doctor Web\Scanning Engine\dwengine.exe [x]
S2 DrWebFwSvc;Dr.Web Firewall Service;c:\program files (x86)\DrWeb\frwl_svc.exe;c:\program files (x86)\DrWeb\frwl_svc.exe [x]
S2 PS3 Media Server;PS3 Media Server;c:\program files (x86)\PS3 Media Server\win32\service\wrapper.exe;c:\program files (x86)\PS3 Media Server\win32\service\wrapper.exe [x]
S2 tmInstall;Thrustmaster Device Driver Installer;c:\program files\Thrustmaster\T500 RS Racing wheel\drivers\amd64\tmInstall.EXE;c:\program files\Thrustmaster\T500 RS Racing wheel\drivers\amd64\tmInstall.EXE [x]
S3 bbcap;bb_capture_driver;c:\windows\system32\DRIVERS\bbcap.sys;c:\windows\SYSNATIVE\DRIVERS\bbcap.sys [x]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 DrWebPF;DrWeb Packet Filter Driver;c:\windows\system32\DRIVERS\DrWebPF.sys;c:\windows\SYSNATIVE\DRIVERS\DrWebPF.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-05 c:\windows\Tasks\Dr.Web Daily scan.job
- c:\program files (x86)\DrWeb\drweb32w.exe [2011-07-12 09:04]
.
2013-09-22 c:\windows\Tasks\Dr.Web Update.job
- c:\program files (x86)\DrWeb\DrWebUpW.exe [2011-06-27 09:43]
.
2013-09-22 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-03-08 10:28]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-19 07:47]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-19 07:47]
.
2013-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4213455190-1121324071-2762663974-1000Core.job
- c:\users\Pater\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-27 06:11]
.
2013-09-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4213455190-1121324071-2762663974-1000UA.job
- c:\users\Pater\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-27 06:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = 127.0.0.1
IE: + Offline &Explorer: Download the link - file://c:\program files (x86)\Offline Explorer\Add_UrlO.htm
IE: + Offline E&xplorer: Download the current page - file://c:\program files (x86)\Offline Explorer\Add_AllO.htm
IE: Download All by ASUS Download - c:\program files (x86)\ASUS\RT-N16 Wireless Router Utilities\ASDownloadAll.htm
IE: Download using ASUS Download - c:\program files (x86)\ASUS\RT-N16 Wireless Router Utilities\ASDownload.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
LSP: c:\program files (x86)\DrWeb\drwebsp.dll
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojebanka.cz
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Pater\AppData\Roaming\Mozilla\Firefox\Profiles\mrkx3zot.default\
FF - ExtSQL: !HIDDEN! 2011-07-13 13:56; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-1771865536.www.idoklad.cz - c:\program files (x86)\Microsoft Silverlight\4.0.60310.0\Silverlight.Configuration.exe
AddRemove-2298590302.www.microsoft.com - c:\program files (x86)\Microsoft Silverlight\4.0.60310.0\Silverlight.Configuration.exe
.
.
"ImagePath"="system32\drivers\dwprot.sys"
"Name"="ImagePath"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-4213455190-1121324071-2762663974-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ED27F17A-65D3-59BB-C227-2061B01D39AE}*]
"maooenhihhfbpeaebomnmafilc"=hex:6f,61,6c,6d,66,6a,70,6b,69,6e,63,6a,66,61,67,
6c,63,61,67,63,6f,6e,65,66,68,6c,66,66,65,63,00,00
"abpopmpgchhplpilikilhpmbgbokhcfbkg"=hex:69,61,65,6f,6b,69,67,64,6b,66,66,61,
6f,65,6a,66,64,70,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="DCC2885B1D784C745984E13C63D57664B6F44391B696D6D43EB3DE1581C1171D66E99F61D4F6DD2DAA41B4D5C6572498EDB3AD4761B610EBF72CA1FC1FA5EFD6F56BEA85FDBEB62313C773511AD113019F3D8DAB5CD20C1CC744FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794A6A0AC4980AC79333C366C9A23FE34FCE727BD2E66FAC0FC18279F3479608FFD77D6CE099135A15B64468E004768035A4E64DA5FB66E8207233EA09E3028F9E1401011FCFE1D21D90922FD653A01F71D7904CA24238EBB2E5000E7EA20AE6BD9CFF16025B774E06B02EA001BA7DDF63E161AF46903753E9949921C4368B54859665CC68745BFF4EFC6CF1C25236963AFF6CB03D08F13E2655A33AB860ECC77CBE8BD90E09355F63F779820BD23DE28D1945663306B2601A2F2B2424777DCE50C5F1D4CA074630223D39F9DCF834FB3FC0909481098C47954A5F4544BF39E026DF8934F691FE7B858C3D16A7C009FF5FB13462730FD5B2FF12CF0198D32A3BFB2844EB193AAB6BE1250B31E193D09E58E16863B7F67A40769E1B40C3DC64C1716F70DCEAA16F73C7626D917ACBF18FB6618D281A584346D1945DFEBBBABD183C3EB27C6ED4227DD9E196FF6F373ACB62B45CC3DFA6970D055FCA6BA21BA3C05DD9D067E50731556199E322161A6FC17776B26738D8B10A2E5CED14236356B9EF8ECA59E7A55E357E7CFF33F170A90A35B7DA7EE9D4724D98827BD0C7B4013D89EE09612C7F38C1C026B9C3F6EB64566D814ABBE22DB8C716B9659662164383EC99F808946C0DADFCE53A4D1F3254B6B686721B345ED80E8B3CFA9668F8C385FEE771B78BA116DE2AF8C9B6CE834A6C472588C63E10388C1F8AB4761DF8B3FCEEF5AB3989D9E3AEAF3C123C7C0263288586904290C080383C6A6DEF36192D0A5A75B2C64988686C063C172E0A52298D06DC03324094BA0B71DDE30FC973DC47E62B4F91D8C4AEFAF37FBD1F97231DBBAF5AA58345001E8ED71198E9E3785457AE0C2A5478C4F650A1D082297B744D0E72F15490191C034B8AA3E63C1AB4D50BA58054CA9DFDE2BA23820D382BAAA9FFEC791EAF4AD05312EA458AA8F92D83968722321D18128D8D39DA06D47F31CC4A7635AB93D3AACE1E8309875F840CF27AFCC64E68EA2395978D78D0AB88FB3929097C7C44B80FC1B89905267303A3F153FF536F7F42589EC73E48B566BED6E2C6BEF592FD6FD9C872FFDFDB8AC3B17504BF4A8C05CA1F2A828B66396B7A4B08AEE6CB2315A6396A384A5B735A8B1ABFD0C4271C4E16331F2FEB2859FBBFABEFAD2FD999312985AC231A53D3D24BF3692BBCB691765E9E708643402DCD86E449ED58E79B80235BC8964137546E2BB525A"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-09-22 20:00:44 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-22 18:00
.
Před spuštěním: Volných bajtů: 127 887 958 016
Po spuštění: Volných bajtů: 127 512 272 896
.
- - End Of File - - CAC3C1E39AE4B9B626E39B6613934182
A36C5E4F47E84449FF07ED3517B43A31