ComboFix 13-12-24.01 - EkZiT 24.12.2013 14:40:29.4.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.6142.4270 [GMT 1:00]
Spuštěný z: c:\users\EkZiT\Downloads\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\EkZiT\Downloads\Desktop\cfscript.txt
FW: COMODO Firewall *Enabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
SP: COMODO Antivirus *Disabled/Outdated* {0C2D2636-923D-EE52-2A83-E643204A8275}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Desktop\Install
c:\users\EkZiT\AppData\Local\Google\Desktop\Install
.
Nakažená kopie c:\windows\explorer.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
.
Nakažená kopie c:\windows\System32\UxTheme.dll byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-uxtheme_31bf3856ad364e35_6.1.7600.16385_none_01d98c7b2040a1b9\uxtheme.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-24 do 2013-12-24 )))))))))))))))))))))))))))))))
.
.
2013-12-24 13:49 . 2013-12-24 13:52 -------- d-----w- c:\users\EkZiT\AppData\Local\temp
2013-12-24 13:49 . 2013-12-24 13:49 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-12-24 13:49 . 2013-12-24 13:49 -------- d-----w- c:\users\repair\AppData\Local\temp
2013-12-24 13:49 . 2013-12-24 13:49 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-12-24 13:49 . 2013-12-24 13:49 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-12-24 13:49 . 2013-12-24 13:49 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2013-12-24 13:49 . 2013-12-24 13:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-24 13:49 . 2013-12-24 13:49 -------- d-----w- c:\users\AppData\AppData\Local\temp
2013-12-24 08:11 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28162E42-60A2-4FBD-BDA2-B5D90CB69EBE}\mpengine.dll
2013-12-23 22:12 . 2013-12-23 22:12 119808 ----a-r- c:\users\EkZiT\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2013-12-23 22:04 . 2013-12-23 22:04 -------- d-----w- c:\program files (x86)\WinToFlash Suggestor
2013-12-23 07:48 . 2013-12-23 07:48 9728 ----a-w- c:\windows\system32\drivers\umpass.sys.bak
2013-12-23 07:44 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-23 07:44 . 2013-12-23 07:44 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-23 07:32 . 2013-12-23 07:32 -------- d-----w- C:\found.000
2013-12-23 07:10 . 2013-12-23 07:25 -------- d-----w- C:\AdwCleaner
2013-12-23 07:01 . 2013-12-23 07:15 -------- d-----w- C:\rsit
2013-12-23 07:01 . 2013-12-23 07:01 -------- d-----w- c:\program files\trend micro
2013-12-23 06:53 . 2013-12-23 06:53 -------- d-----w- C:\FRST
2013-12-23 05:34 . 2013-12-23 05:34 -------- d-----w- c:\users\EkZiT\AppData\Roaming\Malwarebytes
2013-12-23 04:14 . 2013-12-23 04:14 -------- d-----w- c:\programdata\HP
2013-12-23 04:08 . 2013-12-23 04:08 15856 ----a-w- c:\users\cc_20131223_050851.reg
2013-12-20 21:39 . 2013-12-05 08:42 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-12-20 21:39 . 2013-12-05 08:42 32544 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-12-14 23:51 . 2013-12-14 23:51 -------- d-----w- c:\users\EkZiT\AppData\Roaming\Proxy Studios
2013-12-14 22:35 . 2013-12-14 22:35 -------- d-----w- c:\users\EkZiT\AppData\Roaming\Gomo
2013-12-14 21:54 . 2013-12-14 21:54 -------- d-----w- C:\Games
2013-12-12 13:39 . 2013-03-07 08:49 16256 ----a-w- c:\windows\system32\EuEpmGdi.dll
2013-12-12 13:39 . 2013-04-11 13:10 2498216 ----a-w- c:\windows\SysWow64\BootMan.exe
2013-12-12 13:39 . 2013-03-28 18:02 3376640 ----a-w- c:\windows\system32\BootMan.exe
2013-12-12 13:39 . 2013-03-07 08:49 9160 ----a-w- c:\windows\SysWow64\EuGdiDrv.sys
2013-12-12 13:39 . 2013-03-07 08:49 87112 ----a-w- c:\windows\SysWow64\setupempdrv03.exe
2013-12-12 13:39 . 2013-03-07 08:49 13896 ----a-w- c:\windows\SysWow64\epmntdrv.sys
2013-12-12 13:39 . 2013-03-07 08:49 9800 ----a-w- c:\windows\system32\EuGdiDrv.sys
2013-12-12 13:39 . 2013-03-07 08:49 17480 ----a-w- c:\windows\system32\epmntdrv.sys
2013-12-12 13:39 . 2013-03-07 08:49 100936 ----a-w- c:\windows\system32\setupempdrvx64.exe
2013-12-12 13:39 . 2013-03-07 08:49 19840 ----a-w- c:\windows\SysWow64\EuEpmGdi.dll
2013-12-12 13:39 . 2013-12-12 13:39 -------- d-----w- c:\program files (x86)\EaseUS
2013-12-02 17:08 . 2013-12-08 13:55 -------- d-----w- C:\____new
2013-11-29 18:46 . 2013-11-29 18:46 -------- d-----w- C:\debug
2013-11-29 18:45 . 2013-12-23 06:24 -------- d-----w- c:\program files (x86)\Windows Doctor
2013-11-29 13:56 . 2013-11-29 13:56 63488 ----a-w- c:\users\EkZiT\xobglu16.dll
2013-11-29 00:21 . 2013-11-29 00:21 128796 ----a-w- c:\users\cc_20131129_012109.reg
2013-11-27 01:38 . 2013-11-27 01:40 3140 --sha-w- c:\windows\SysWow64\KGyGaAvL.sys
2013-11-27 01:38 . 2013-11-27 01:38 8 --sh--r- c:\windows\SysWow64\2912DA9DF7.sys
2013-11-27 01:38 . 2013-11-27 01:38 -------- d-----w- c:\users\EkZiT\AppData\Roaming\Corel
2013-11-27 01:36 . 2013-11-27 01:36 65536 ----a-r- c:\users\EkZiT\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
2013-11-27 01:35 . 2013-11-27 01:35 -------- d-----w- c:\program files (x86)\Common Files\Protexis
2013-11-27 01:34 . 2013-11-27 01:34 -------- d-----w- c:\programdata\Corel
2013-11-27 01:34 . 2013-11-27 01:34 -------- d-----w- c:\program files (x86)\Corel
2013-11-27 01:34 . 2013-11-27 01:34 -------- d-----w- c:\program files (x86)\Common Files\Corel
2013-11-27 01:18 . 2013-11-27 01:18 -------- d-----w- c:\users\EkZiT\AppData\Roaming\Autodesk
2013-11-27 01:18 . 2013-11-27 01:18 -------- d-----w- c:\programdata\Alias
2013-11-26 23:32 . 2013-11-26 23:45 -------- d-----w- c:\program files (x86)\Need For Speed Rivals
2013-11-26 20:01 . 2013-11-26 20:01 -------- d-----w- c:\users\EkZiT\AppData\Roaming\dekovir
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-24 01:24 . 2011-12-11 07:43 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-12-24 01:24 . 2011-10-07 21:11 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-12-24 01:23 . 2011-12-11 07:43 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-12-20 21:29 . 2011-12-11 07:43 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-12-16 02:00 . 2010-06-03 14:00 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-10 23:18 . 2012-11-18 20:31 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-10 23:18 . 2011-08-06 05:26 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-10 02:13 . 2013-11-20 16:46 982232 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-12-10 02:13 . 2013-11-20 16:46 1100248 ----a-w- c:\windows\system32\nvspcap64.dll
2013-12-05 08:42 . 2013-10-02 00:03 35104 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-11-20 11:36 . 2013-11-20 11:36 27760 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2013-11-20 11:36 . 2013-11-20 11:36 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-11-20 11:36 . 2013-11-20 11:36 14448 ----a-w- c:\windows\system32\drivers\ggflt.sys
2013-11-19 02:33 . 2010-05-24 17:48 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-14 11:56 . 2013-10-02 01:49 18293608 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-11-14 11:56 . 2013-11-20 16:51 15862272 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-11-14 11:56 . 2013-11-20 16:51 1242400 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2013-11-14 11:56 . 2012-03-14 19:27 1436528 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-11-14 11:56 . 2013-11-20 16:51 9619872 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-11-14 11:56 . 2013-11-20 16:51 11514624 ----a-w- c:\windows\system32\nvopencl.dll
2013-11-14 11:56 . 2013-10-02 01:49 30361888 ----a-w- c:\windows\system32\nvoglv64.dll
2013-11-14 11:56 . 2013-11-20 16:51 317472 ----a-w- c:\windows\system32\nvoglshim64.dll
2013-11-14 11:56 . 2013-11-20 16:51 22951200 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-11-14 11:56 . 2013-11-20 16:51 266984 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2013-11-14 11:56 . 2013-11-20 16:51 12613408 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-11-14 11:56 . 2013-11-20 16:51 707360 ----a-w- c:\windows\system32\NvFBC64.dll
2013-11-14 11:56 . 2013-11-20 16:51 657184 ----a-w- c:\windows\system32\NvIFR64.dll
2013-11-14 11:56 . 2013-11-20 16:51 609568 ----a-w- c:\windows\SysWow64\NvFBC.dll
2013-11-14 11:56 . 2013-11-20 16:51 562464 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-11-14 11:56 . 2013-11-20 16:51 168616 ----a-w- c:\windows\system32\nvinitx.dll
2013-11-14 11:56 . 2013-11-20 16:51 1511712 ----a-w- c:\windows\system32\nvdispgenco6433182.dll
2013-11-14 11:56 . 2013-11-20 16:51 141336 ----a-w- c:\windows\SysWow64\nvinit.dll
2013-11-14 11:56 . 2013-11-20 16:51 1884448 ----a-w- c:\windows\system32\nvdispco6433182.dll
2013-11-14 11:56 . 2013-11-20 16:51 18208624 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-11-14 11:56 . 2013-10-02 01:49 15218504 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-11-14 11:56 . 2013-11-20 16:51 3132704 ----a-w- c:\windows\system32\nvcuvid.dll
2013-11-14 11:56 . 2013-11-20 16:51 2947872 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2013-11-14 11:56 . 2013-11-20 16:51 9691888 ----a-w- c:\windows\SysWow64\nvcuda.dll
2013-11-14 11:56 . 2013-11-20 16:51 3125024 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-11-14 11:56 . 2013-11-20 16:51 2747680 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2013-11-14 11:56 . 2013-11-20 16:51 11600432 ----a-w- c:\windows\system32\nvcuda.dll
2013-11-14 11:56 . 2013-11-20 16:51 25257248 ----a-w- c:\windows\system32\nvcompiler.dll
2013-11-14 11:56 . 2013-11-20 16:51 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2013-11-14 11:56 . 2013-10-02 01:49 3069608 ----a-w- c:\windows\system32\nvapi64.dll
2013-11-14 11:56 . 2013-10-02 01:49 2697248 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-11-14 11:38 . 2013-07-08 19:59 709144 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2013-11-14 11:38 . 2013-06-18 14:15 43216 ----a-w- c:\windows\system32\cmdcsr.dll
2013-11-11 15:02 . 2012-03-12 19:21 6674208 ----a-w- c:\windows\system32\nvcpl.dll
2013-11-11 15:02 . 2012-03-12 19:21 3490080 ----a-w- c:\windows\system32\nvsvc64.dll
2013-11-11 15:01 . 2012-03-12 19:21 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-11-11 15:01 . 2012-03-12 19:21 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-11-11 15:01 . 2012-03-12 19:21 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-11-11 15:01 . 2012-03-12 19:21 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-11-11 15:01 . 2012-03-14 19:28 3467927 ----a-w- c:\windows\system32\nvcoproc.bin
2013-11-11 07:59 . 2013-11-11 07:59 590112 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-10-23 10:30 . 2013-11-08 16:15 1511712 ----a-w- c:\windows\system32\nvdispgenco6433165.dll
2013-10-23 10:30 . 2013-11-08 16:15 1884448 ----a-w- c:\windows\system32\nvdispco6433165.dll
2013-10-12 02:30 . 2013-11-14 01:28 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-14 01:28 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-14 01:28 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-14 01:28 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-14 01:28 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-08 06:50 . 2013-11-21 15:26 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-05 20:25 . 2013-11-14 01:28 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-14 01:28 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-10-04 02:28 . 2013-11-14 01:28 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-14 01:28 197120 ----a-w- c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-14 01:28 1930752 ----a-w- c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-14 01:28 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56 . 2013-11-14 01:28 168960 ----a-w- c:\windows\SysWow64\credui.dll
2013-10-04 01:56 . 2013-11-14 01:28 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-10-03 02:23 . 2013-11-14 01:28 404480 ----a-w- c:\windows\system32\gdi32.dll
2013-10-03 02:00 . 2013-11-14 01:28 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-10-03 01:04 . 2012-01-28 14:54 188128 ----a-w- c:\programdata\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2013-09-28 01:09 . 2013-11-14 01:28 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-27 08:57 . 2013-10-02 01:49 1884448 ----a-w- c:\windows\system32\nvdispco6433140.dll
2013-09-27 08:57 . 2013-10-02 01:49 1511712 ----a-w- c:\windows\system32\nvdispgenco6433140.dll
2010-01-26 09:11 . 2013-02-16 17:02 444283 ----a-w- c:\program files\Common Files\WinPcapNmap.exe
2009-12-06 09:18 26624 --sh--w- c:\windows\bfcs2.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD}]
2012-05-25 15:38 281424 ----a-w- c:\program files (x86)\WinToFlash Suggestor\WinToFlashSuggestor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuMyGames"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fsproflt2]
@="Service"
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys;c:\windows\SYSNATIVE\drivers\TfFsMon.sys [x]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys;c:\windows\SYSNATIVE\drivers\TfSysMon.sys [x]
R0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
R1 ntiomin;ntiomin; [x]
R1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys;c:\windows\SYSNATIVE\DRIVERS\vdrv1000.sys [x]
R1 WinFPdrv;WinFPdrv;SysWOW64\WinFPdrv.sys;SysWOW64\WinFPdrv.sys [x]
R2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 atillk64;atillk64;c:\program files (x86)\AMD\System Monitor\atillk64.sys;c:\program files (x86)\AMD\System Monitor\atillk64.sys [x]
R3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver;c:\windows\system32\DRIVERS\BazisVirtualCDBus.sys;c:\windows\SYSNATIVE\DRIVERS\BazisVirtualCDBus.sys [x]
R3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x]
R3 cpuz130;cpuz130;c:\users\EkZiT\AppData\Local\Temp\cpuz130\cpuz_x64.sys;c:\users\EkZiT\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys;c:\windows\SYSNATIVE\epmntdrv.sys [x]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys;c:\windows\SYSNATIVE\EuGdiDrv.sys [x]
R3 FLASHSYS;FLASHSYS;c:\program files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys;c:\program files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 HDJCtrl;Hercules DJ Control MP3 Service;c:\windows\system32\Drivers\HDJCtrl.sys;c:\windows\SYSNATIVE\Drivers\HDJCtrl.sys [x]
R3 HDJMidi;Hercules DJ Control MP3 MIDI;c:\windows\system32\DRIVERS\HDJMidi.sys;c:\windows\SYSNATIVE\DRIVERS\HDJMidi.sys [x]
R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys;c:\windows\SYSNATIVE\drivers\HH10Help.sys [x]
R3 JakNDisMP;JakNDisMP;c:\windows\system32\DRIVERS\JakNDis.sys;c:\windows\SYSNATIVE\DRIVERS\JakNDis.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [x]
R3 MSICDSetup;MSICDSetup;e:\cdriver64.sys;e:\CDriver64.sys [x]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update 4\LU4\NTIOLib_X64.sys;c:\program files (x86)\MSI\Live Update 4\LU4\NTIOLib_X64.sys [x]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis64.sys;c:\windows\SYSNATIVE\DRIVERS\pctNdis64.sys [x]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SaiK0CEA;SaiK0CEA;c:\windows\system32\DRIVERS\SaiK0CEA.sys;c:\windows\SYSNATIVE\DRIVERS\SaiK0CEA.sys [x]
R3 SaiU0CEA;SaiU0CEA;c:\windows\system32\DRIVERS\SaiU0CEA.sys;c:\windows\SYSNATIVE\DRIVERS\SaiU0CEA.sys [x]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys;c:\windows\SYSNATIVE\drivers\TfNetMon.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [x]
S0 FSProFilter2;FSPro File Filter 2;c:\windows\System32\Drivers\FSPFltd2.sys;c:\windows\SYSNATIVE\Drivers\FSPFltd2.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AODDriver4.2.0;AODDriver4.2.0;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [x]
S2 fsproflt2;FSPro Filter Service 2;c:\windows\SysWOW64\fsproflt2.exe;c:\windows\SysWOW64\fsproflt2.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys;c:\windows\SYSNATIVE\DRIVERS\seehcri.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
S3 VMfilt;VMfilt;c:\windows\system32\drivers\VMfilt64.sys;c:\windows\SYSNATIVE\drivers\VMfilt64.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-18 23:18]
.
2013-12-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-28354313-2184747063-3306077547-1000Core.job
- c:\users\EkZiT\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-26 04:36]
.
2013-12-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-28354313-2184747063-3306077547-1000UA.job
- c:\users\EkZiT\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-26 04:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2012-11-29 7406392]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2013-11-11 1612504]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-08 1028384]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-12-10 1100248]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
------- Doplňkový sken -------
.
mStart Page = hxxp://
www.google.com
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: Stáhnout s Mipony
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.235.1
TCP: Interfaces\{CEEBD37D-F1B9-4569-9EFC-16CAC7FB1836}: NameServer = 156.154.70.25,156.154.71.25
FF - ProfilePath - c:\users\EkZiT\AppData\Roaming\Mozilla\Firefox\Profiles\8124rlsi.default\
FF - ExtSQL: !HIDDEN! 2012-06-01 21:08;
smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-ESN Sonar-0.70.4 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
AddRemove-metaCrawler - c:\program files (x86)\metaCrawler\1.8.19.0\uninstall.exe
AddRemove-Wubi - f:\ubuntu\uninstall-wubi.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\vdrv1000]
"ImagePath"="system32\DRIVERS\vdrv1000.sys"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\program files\Hide Folders 2012\hf.exe
c:\program files (x86)\ASUS\TurboV EVO\TurboVHELP.exe
c:\windows\DAODx.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Common Files\Protexis\License Service\PSIService.exe
.
**************************************************************************
.
Celkový čas: 2013-12-24 14:58:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-12-24 13:58
ComboFix2.txt 2013-12-24 12:50
.
Před spuštěním: 4 729 442 304
Po spuštění: 4 226 134 016
.
- - End Of File - - 7CBBC960024D305D42C47332DB52D2FD
413FC2A0C716421B3158746D63736515