Pomalé PC s WIN 7 Ultimate
Napsal: 06 říj 2013 20:19
Ahoj,
PC je nějaké pomalé, zde jsou logy:
ComboFix 13-10-04.02 - Radek a Hanka 06.10.2013 20:58:10.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.1112 [GMT 2:00]
Spuštěný z: c:\users\Radek a Hanka\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-09-06 do 2013-10-06 )))))))))))))))))))))))))))))))
.
.
2013-10-06 19:05 . 2013-10-06 19:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-06 19:05 . 2013-10-06 19:05 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2013-10-06 14:55 . 2013-10-06 14:55 -------- d-----w- c:\programdata\PC-Doctor for Windows
2013-10-06 14:54 . 2013-10-06 14:55 -------- d-----w- c:\program files\My Dell
2013-10-06 14:42 . 2013-10-06 14:42 -------- d-----w- c:\programdata\Auslogics
2013-10-06 11:46 . 2013-09-15 22:50 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3A996358-3EF3-42E4-9EF0-E35A3118413F}\mpengine.dll
2013-10-06 11:01 . 2013-10-06 11:01 615936 ----a-w- c:\windows\AutoKMS.exe
2013-10-04 15:01 . 2013-10-04 15:01 -------- d-----w- c:\programdata\DivoGames
2013-10-04 15:00 . 2013-10-04 15:01 -------- d-----w- c:\program files (x86)\Poklady starověké sluje
2013-09-30 20:41 . 2013-09-30 20:41 -------- d-----w- C:\dell
2013-09-30 13:09 . 2013-09-30 13:09 -------- d-----w- c:\users\Radek a Hanka\AppData\Roaming\Malwarebytes
2013-09-30 13:08 . 2013-09-30 13:08 -------- d-----w- c:\programdata\Malwarebytes
2013-09-30 12:53 . 2013-09-30 12:53 -------- d-----w- c:\users\Radek a Hanka\AppData\Roaming\SUPERAntiSpyware.com
2013-09-20 14:31 . 2013-10-06 14:19 -------- d-----w- c:\users\Radek a Hanka\AppData\Local\Diagnostics
2013-09-19 17:42 . 2013-09-19 17:42 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-09-19 17:42 . 2013-09-19 17:42 -------- d-----w- c:\programdata\Oracle
2013-09-19 17:41 . 2013-09-19 17:41 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-19 17:41 . 2013-09-19 17:41 -------- d-----w- c:\program files (x86)\Java
2013-09-09 10:42 . 2013-09-09 10:42 -------- d-----w- c:\program files\Return to Castle Wolfenstein
2013-09-09 08:42 . 2013-10-06 14:46 -------- d-----w- c:\program files (x86)\Return to Castle Wolfenstein
2013-09-09 08:41 . 2001-06-19 15:53 266293 ----a-w- c:\windows\SysWow64\temp.001
2013-09-09 08:40 . 2001-06-19 15:53 266293 ----a-w- c:\windows\SysWow64\temp.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 17:41 . 2013-05-08 11:35 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-09-19 17:41 . 2013-05-08 11:35 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-09-10 19:15 . 2013-05-07 22:46 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-10 19:15 . 2013-05-07 22:46 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-30 07:48 . 2013-05-07 22:07 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2013-05-07 22:07 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2013-05-07 22:07 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2013-05-07 22:07 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2013-05-07 22:07 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2013-05-07 22:07 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2013-05-07 22:07 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2013-05-07 22:07 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2013-05-07 22:07 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2013-05-07 22:07 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-07 02:22 . 2013-05-07 22:15 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-07-22 09:32 . 2013-07-22 09:32 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-07-22 09:32 . 2013-07-22 09:32 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-07-22 09:32 . 2013-07-22 09:32 85504 ----a-w- c:\windows\system32\jsproxy.dll
2013-07-22 09:32 . 2013-07-22 09:32 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-07-22 09:32 . 2013-07-22 09:32 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-07-22 09:32 . 2013-07-22 09:32 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-07-22 09:32 . 2013-07-22 09:32 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-07-22 09:32 . 2013-07-22 09:32 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-07-22 09:32 . 2013-07-22 09:32 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-07-22 09:32 . 2013-07-22 09:32 367104 ----a-w- c:\windows\SysWow64\html.iec
2013-07-22 09:32 . 2013-07-22 09:32 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-07-22 09:32 . 2013-07-22 09:32 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-07-22 09:32 . 2013-07-22 09:32 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-07-22 09:32 . 2013-07-22 09:32 222208 ----a-w- c:\windows\system32\msls31.dll
2013-07-22 09:32 . 2013-07-22 09:32 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-07-22 09:32 . 2013-07-22 09:32 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2013-07-22 09:32 . 2013-07-22 09:32 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2013-07-22 09:32 . 2013-07-22 09:32 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-07-22 09:32 . 2013-07-22 09:32 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-07-22 09:32 . 2013-07-22 09:32 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-07-22 09:32 . 2013-07-22 09:32 1392128 ----a-w- c:\windows\system32\wininet.dll
2013-07-22 09:32 . 2013-07-22 09:32 1346560 ----a-w- c:\windows\system32\urlmon.dll
2013-07-22 09:32 . 2013-07-22 09:32 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2013-07-22 09:32 . 2013-07-22 09:32 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2013-07-22 09:32 . 2013-07-22 09:32 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-07-22 09:32 . 2013-07-22 09:32 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2013-07-22 09:32 . 2013-07-22 09:32 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-07-22 09:32 . 2013-07-22 09:32 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-22 09:32 . 2013-07-22 09:32 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2013-07-22 09:32 . 2013-07-22 09:32 85504 ----a-w- c:\windows\system32\iesetup.dll
2013-07-22 09:32 . 2013-07-22 09:32 82432 ----a-w- c:\windows\system32\icardie.dll
2013-07-22 09:32 . 2013-07-22 09:32 816640 ----a-w- c:\windows\system32\jscript.dll
2013-07-22 09:32 . 2013-07-22 09:32 76800 ----a-w- c:\windows\system32\tdc.ocx
2013-07-22 09:32 . 2013-07-22 09:32 729088 ----a-w- c:\windows\system32\msfeeds.dll
2013-07-22 09:32 . 2013-07-22 09:32 65024 ----a-w- c:\windows\system32\pngfilt.dll
2013-07-22 09:32 . 2013-07-22 09:32 599040 ----a-w- c:\windows\system32\vbscript.dll
2013-07-22 09:32 . 2013-07-22 09:32 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-07-22 09:32 . 2013-07-22 09:32 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2013-07-22 09:32 . 2013-07-22 09:32 49664 ----a-w- c:\windows\system32\imgutil.dll
2013-07-22 09:32 . 2013-07-22 09:32 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-07-22 09:32 . 2013-07-22 09:32 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2013-07-22 09:32 . 2013-07-22 09:32 448512 ----a-w- c:\windows\system32\html.iec
2013-07-22 09:32 . 2013-07-22 09:32 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2013-07-22 09:32 . 2013-07-22 09:32 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-07-22 09:32 . 2013-07-22 09:32 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-07-22 09:32 . 2013-07-22 09:32 30720 ----a-w- c:\windows\system32\licmgr10.dll
2013-07-22 09:32 . 2013-07-22 09:32 282112 ----a-w- c:\windows\system32\dxtrans.dll
2013-07-22 09:32 . 2013-07-22 09:32 267776 ----a-w- c:\windows\system32\ieaksie.dll
2013-07-22 09:32 . 2013-07-22 09:32 249344 ----a-w- c:\windows\system32\webcheck.dll
2013-07-22 09:32 . 2013-07-22 09:32 248320 ----a-w- c:\windows\system32\ieui.dll
2013-07-22 09:32 . 2013-07-22 09:32 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-07-22 09:32 . 2013-07-22 09:32 237056 ----a-w- c:\windows\system32\url.dll
2013-07-22 09:32 . 2013-07-22 09:32 2312704 ----a-w- c:\windows\system32\jscript9.dll
2013-07-22 09:32 . 2013-07-22 09:32 2147840 ----a-w- c:\windows\system32\iertutil.dll
2013-07-22 09:32 . 2013-07-22 09:32 197120 ----a-w- c:\windows\system32\msrating.dll
2013-07-22 09:32 . 2013-07-22 09:32 17829376 ----a-w- c:\windows\system32\mshtml.dll
2013-07-22 09:32 . 2013-07-22 09:32 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2013-07-22 09:32 . 2013-07-22 09:32 165888 ----a-w- c:\windows\system32\iexpress.exe
2013-07-22 09:32 . 2013-07-22 09:32 163840 ----a-w- c:\windows\system32\ieakui.dll
2013-07-22 09:32 . 2013-07-22 09:32 160256 ----a-w- c:\windows\system32\wextract.exe
2013-07-22 09:32 . 2013-07-22 09:32 160256 ----a-w- c:\windows\system32\ieakeng.dll
2013-07-22 09:32 . 2013-07-22 09:32 149504 ----a-w- c:\windows\system32\occache.dll
2013-07-22 09:32 . 2013-07-22 09:32 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2013-07-22 09:32 . 2013-07-22 09:32 145920 ----a-w- c:\windows\system32\iepeers.dll
2013-07-22 09:32 . 2013-07-22 09:32 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-07-22 09:32 . 2013-07-22 09:32 12288 ----a-w- c:\windows\system32\mshta.exe
2013-07-22 09:32 . 2013-07-22 09:32 114176 ----a-w- c:\windows\system32\admparse.dll
2013-07-22 09:32 . 2013-07-22 09:32 111616 ----a-w- c:\windows\system32\iesysprep.dll
2013-07-22 09:32 . 2013-07-22 09:32 10926080 ----a-w- c:\windows\system32\ieframe.dll
2013-07-22 09:32 . 2013-07-22 09:32 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2013-07-22 09:32 . 2013-07-22 09:32 103936 ----a-w- c:\windows\system32\inseng.dll
2013-07-22 09:30 . 2013-07-22 09:30 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-07-22 09:30 . 2013-07-22 09:30 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-07-22 09:30 . 2013-07-22 09:30 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-22 09:30 . 2013-07-22 09:30 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-22 09:30 . 2013-07-22 09:30 144384 ----a-w- c:\windows\system32\cdd.dll
2013-07-22 09:30 . 2013-07-22 09:30 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2013-07-22 09:30 . 2013-07-22 09:30 470016 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-07-22 09:30 . 2013-07-22 09:30 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2013-07-22 09:30 . 2013-07-22 09:30 4068864 ----a-w- c:\windows\system32\mf.dll
2013-07-22 09:30 . 2013-07-22 09:30 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2013-07-22 09:30 . 2013-07-22 09:30 283648 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-07-22 09:30 . 2013-07-22 09:30 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-07-22 09:30 . 2013-07-22 09:30 229888 ----a-w- c:\windows\system32\XpsRasterService.dll
2013-07-22 09:30 . 2013-07-22 09:30 206848 ----a-w- c:\windows\system32\mfps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432]
"Seznam Postak"="c:\program files (x86)\Seznam.cz\postak.exe" [2010-10-06 488728]
"cz.seznam.software.autoupdate"="c:\users\Radek a Hanka\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\Radek a Hanka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2013-03-21 1061960]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-05 18:47 1185744 ----a-w- c:\program files (x86)\Google\Chrome\Application\30.0.1599.69\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-07 19:15]
.
2013-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-07 22:31]
.
2013-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-07 22:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-12-10 323584]
"AutoKMS"="c:\windows\AutoKMS.exe" [2013-10-06 615936]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/?clid=12
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: dell.com
TCP: DhcpNameServer = 91.217.52.2 91.217.52.3
FF - ProfilePath - c:\users\Radek a Hanka\AppData\Roaming\Mozilla\Firefox\Profiles\elcv2g3b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
"Key"="ActionsPane3"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-10-06 21:08:46
ComboFix-quarantined-files.txt 2013-10-06 19:08
.
Před spuštěním: Volných bajtů: 77 030 936 576
Po spuštění: Volných bajtů: 81 980 948 480
.
- - End Of File - - 4DC7C5D9E2D851860FE99093C582DAFC
A36C5E4F47E84449FF07ED3517B43A31
PC je nějaké pomalé, zde jsou logy:
ComboFix 13-10-04.02 - Radek a Hanka 06.10.2013 20:58:10.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2046.1112 [GMT 2:00]
Spuštěný z: c:\users\Radek a Hanka\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-09-06 do 2013-10-06 )))))))))))))))))))))))))))))))
.
.
2013-10-06 19:05 . 2013-10-06 19:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-06 19:05 . 2013-10-06 19:05 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2013-10-06 14:55 . 2013-10-06 14:55 -------- d-----w- c:\programdata\PC-Doctor for Windows
2013-10-06 14:54 . 2013-10-06 14:55 -------- d-----w- c:\program files\My Dell
2013-10-06 14:42 . 2013-10-06 14:42 -------- d-----w- c:\programdata\Auslogics
2013-10-06 11:46 . 2013-09-15 22:50 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3A996358-3EF3-42E4-9EF0-E35A3118413F}\mpengine.dll
2013-10-06 11:01 . 2013-10-06 11:01 615936 ----a-w- c:\windows\AutoKMS.exe
2013-10-04 15:01 . 2013-10-04 15:01 -------- d-----w- c:\programdata\DivoGames
2013-10-04 15:00 . 2013-10-04 15:01 -------- d-----w- c:\program files (x86)\Poklady starověké sluje
2013-09-30 20:41 . 2013-09-30 20:41 -------- d-----w- C:\dell
2013-09-30 13:09 . 2013-09-30 13:09 -------- d-----w- c:\users\Radek a Hanka\AppData\Roaming\Malwarebytes
2013-09-30 13:08 . 2013-09-30 13:08 -------- d-----w- c:\programdata\Malwarebytes
2013-09-30 12:53 . 2013-09-30 12:53 -------- d-----w- c:\users\Radek a Hanka\AppData\Roaming\SUPERAntiSpyware.com
2013-09-20 14:31 . 2013-10-06 14:19 -------- d-----w- c:\users\Radek a Hanka\AppData\Local\Diagnostics
2013-09-19 17:42 . 2013-09-19 17:42 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-09-19 17:42 . 2013-09-19 17:42 -------- d-----w- c:\programdata\Oracle
2013-09-19 17:41 . 2013-09-19 17:41 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-19 17:41 . 2013-09-19 17:41 -------- d-----w- c:\program files (x86)\Java
2013-09-09 10:42 . 2013-09-09 10:42 -------- d-----w- c:\program files\Return to Castle Wolfenstein
2013-09-09 08:42 . 2013-10-06 14:46 -------- d-----w- c:\program files (x86)\Return to Castle Wolfenstein
2013-09-09 08:41 . 2001-06-19 15:53 266293 ----a-w- c:\windows\SysWow64\temp.001
2013-09-09 08:40 . 2001-06-19 15:53 266293 ----a-w- c:\windows\SysWow64\temp.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 17:41 . 2013-05-08 11:35 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-09-19 17:41 . 2013-05-08 11:35 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-09-10 19:15 . 2013-05-07 22:46 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-10 19:15 . 2013-05-07 22:46 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-30 07:48 . 2013-05-07 22:07 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2013-05-07 22:07 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2013-05-07 22:07 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2013-05-07 22:07 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2013-05-07 22:07 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2013-05-07 22:07 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2013-05-07 22:07 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2013-05-07 22:07 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2013-05-07 22:07 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2013-05-07 22:07 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-07 02:22 . 2013-05-07 22:15 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-07-22 09:32 . 2013-07-22 09:32 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-07-22 09:32 . 2013-07-22 09:32 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-07-22 09:32 . 2013-07-22 09:32 85504 ----a-w- c:\windows\system32\jsproxy.dll
2013-07-22 09:32 . 2013-07-22 09:32 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-07-22 09:32 . 2013-07-22 09:32 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-07-22 09:32 . 2013-07-22 09:32 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-07-22 09:32 . 2013-07-22 09:32 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-07-22 09:32 . 2013-07-22 09:32 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-07-22 09:32 . 2013-07-22 09:32 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-07-22 09:32 . 2013-07-22 09:32 367104 ----a-w- c:\windows\SysWow64\html.iec
2013-07-22 09:32 . 2013-07-22 09:32 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-07-22 09:32 . 2013-07-22 09:32 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-07-22 09:32 . 2013-07-22 09:32 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-07-22 09:32 . 2013-07-22 09:32 222208 ----a-w- c:\windows\system32\msls31.dll
2013-07-22 09:32 . 2013-07-22 09:32 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-07-22 09:32 . 2013-07-22 09:32 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2013-07-22 09:32 . 2013-07-22 09:32 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2013-07-22 09:32 . 2013-07-22 09:32 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-07-22 09:32 . 2013-07-22 09:32 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-07-22 09:32 . 2013-07-22 09:32 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-07-22 09:32 . 2013-07-22 09:32 1392128 ----a-w- c:\windows\system32\wininet.dll
2013-07-22 09:32 . 2013-07-22 09:32 1346560 ----a-w- c:\windows\system32\urlmon.dll
2013-07-22 09:32 . 2013-07-22 09:32 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2013-07-22 09:32 . 2013-07-22 09:32 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2013-07-22 09:32 . 2013-07-22 09:32 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-07-22 09:32 . 2013-07-22 09:32 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2013-07-22 09:32 . 2013-07-22 09:32 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-07-22 09:32 . 2013-07-22 09:32 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-22 09:32 . 2013-07-22 09:32 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2013-07-22 09:32 . 2013-07-22 09:32 85504 ----a-w- c:\windows\system32\iesetup.dll
2013-07-22 09:32 . 2013-07-22 09:32 82432 ----a-w- c:\windows\system32\icardie.dll
2013-07-22 09:32 . 2013-07-22 09:32 816640 ----a-w- c:\windows\system32\jscript.dll
2013-07-22 09:32 . 2013-07-22 09:32 76800 ----a-w- c:\windows\system32\tdc.ocx
2013-07-22 09:32 . 2013-07-22 09:32 729088 ----a-w- c:\windows\system32\msfeeds.dll
2013-07-22 09:32 . 2013-07-22 09:32 65024 ----a-w- c:\windows\system32\pngfilt.dll
2013-07-22 09:32 . 2013-07-22 09:32 599040 ----a-w- c:\windows\system32\vbscript.dll
2013-07-22 09:32 . 2013-07-22 09:32 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-07-22 09:32 . 2013-07-22 09:32 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2013-07-22 09:32 . 2013-07-22 09:32 49664 ----a-w- c:\windows\system32\imgutil.dll
2013-07-22 09:32 . 2013-07-22 09:32 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-07-22 09:32 . 2013-07-22 09:32 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2013-07-22 09:32 . 2013-07-22 09:32 448512 ----a-w- c:\windows\system32\html.iec
2013-07-22 09:32 . 2013-07-22 09:32 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2013-07-22 09:32 . 2013-07-22 09:32 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-07-22 09:32 . 2013-07-22 09:32 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-07-22 09:32 . 2013-07-22 09:32 30720 ----a-w- c:\windows\system32\licmgr10.dll
2013-07-22 09:32 . 2013-07-22 09:32 282112 ----a-w- c:\windows\system32\dxtrans.dll
2013-07-22 09:32 . 2013-07-22 09:32 267776 ----a-w- c:\windows\system32\ieaksie.dll
2013-07-22 09:32 . 2013-07-22 09:32 249344 ----a-w- c:\windows\system32\webcheck.dll
2013-07-22 09:32 . 2013-07-22 09:32 248320 ----a-w- c:\windows\system32\ieui.dll
2013-07-22 09:32 . 2013-07-22 09:32 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-07-22 09:32 . 2013-07-22 09:32 237056 ----a-w- c:\windows\system32\url.dll
2013-07-22 09:32 . 2013-07-22 09:32 2312704 ----a-w- c:\windows\system32\jscript9.dll
2013-07-22 09:32 . 2013-07-22 09:32 2147840 ----a-w- c:\windows\system32\iertutil.dll
2013-07-22 09:32 . 2013-07-22 09:32 197120 ----a-w- c:\windows\system32\msrating.dll
2013-07-22 09:32 . 2013-07-22 09:32 17829376 ----a-w- c:\windows\system32\mshtml.dll
2013-07-22 09:32 . 2013-07-22 09:32 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2013-07-22 09:32 . 2013-07-22 09:32 165888 ----a-w- c:\windows\system32\iexpress.exe
2013-07-22 09:32 . 2013-07-22 09:32 163840 ----a-w- c:\windows\system32\ieakui.dll
2013-07-22 09:32 . 2013-07-22 09:32 160256 ----a-w- c:\windows\system32\wextract.exe
2013-07-22 09:32 . 2013-07-22 09:32 160256 ----a-w- c:\windows\system32\ieakeng.dll
2013-07-22 09:32 . 2013-07-22 09:32 149504 ----a-w- c:\windows\system32\occache.dll
2013-07-22 09:32 . 2013-07-22 09:32 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2013-07-22 09:32 . 2013-07-22 09:32 145920 ----a-w- c:\windows\system32\iepeers.dll
2013-07-22 09:32 . 2013-07-22 09:32 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-07-22 09:32 . 2013-07-22 09:32 12288 ----a-w- c:\windows\system32\mshta.exe
2013-07-22 09:32 . 2013-07-22 09:32 114176 ----a-w- c:\windows\system32\admparse.dll
2013-07-22 09:32 . 2013-07-22 09:32 111616 ----a-w- c:\windows\system32\iesysprep.dll
2013-07-22 09:32 . 2013-07-22 09:32 10926080 ----a-w- c:\windows\system32\ieframe.dll
2013-07-22 09:32 . 2013-07-22 09:32 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2013-07-22 09:32 . 2013-07-22 09:32 103936 ----a-w- c:\windows\system32\inseng.dll
2013-07-22 09:30 . 2013-07-22 09:30 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-07-22 09:30 . 2013-07-22 09:30 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-07-22 09:30 . 2013-07-22 09:30 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-22 09:30 . 2013-07-22 09:30 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-22 09:30 . 2013-07-22 09:30 144384 ----a-w- c:\windows\system32\cdd.dll
2013-07-22 09:30 . 2013-07-22 09:30 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2013-07-22 09:30 . 2013-07-22 09:30 470016 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-07-22 09:30 . 2013-07-22 09:30 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2013-07-22 09:30 . 2013-07-22 09:30 4068864 ----a-w- c:\windows\system32\mf.dll
2013-07-22 09:30 . 2013-07-22 09:30 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2013-07-22 09:30 . 2013-07-22 09:30 283648 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-07-22 09:30 . 2013-07-22 09:30 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-07-22 09:30 . 2013-07-22 09:30 229888 ----a-w- c:\windows\system32\XpsRasterService.dll
2013-07-22 09:30 . 2013-07-22 09:30 206848 ----a-w- c:\windows\system32\mfps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432]
"Seznam Postak"="c:\program files (x86)\Seznam.cz\postak.exe" [2010-10-06 488728]
"cz.seznam.software.autoupdate"="c:\users\Radek a Hanka\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\Radek a Hanka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2013-03-21 1061960]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-05 18:47 1185744 ----a-w- c:\program files (x86)\Google\Chrome\Application\30.0.1599.69\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-07 19:15]
.
2013-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-07 22:31]
.
2013-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-07 22:31]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-12-10 323584]
"AutoKMS"="c:\windows\AutoKMS.exe" [2013-10-06 615936]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/?clid=12
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: dell.com
TCP: DhcpNameServer = 91.217.52.2 91.217.52.3
FF - ProfilePath - c:\users\Radek a Hanka\AppData\Roaming\Mozilla\Firefox\Profiles\elcv2g3b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
"Key"="ActionsPane3"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-10-06 21:08:46
ComboFix-quarantined-files.txt 2013-10-06 19:08
.
Před spuštěním: Volných bajtů: 77 030 936 576
Po spuštění: Volných bajtů: 81 980 948 480
.
- - End Of File - - 4DC7C5D9E2D851860FE99093C582DAFC
A36C5E4F47E84449FF07ED3517B43A31