Neshta, log ComboFix
Napsal: 11 črc 2015 23:03
Dobrý den,
objevila se mi v PC potvora Neshta. Kamarád mi doporučil ComboFix.
Neshta se mi stále objevuje, již sem odinstaloval Spybot. Používám antivir Avira.
Zde přikládám log z ComboFixu,
děkuji moc za kontrolu..
***********************************************************************************************************************
ComboFix 15-07-10.01 - user . 07. 2015 22:52:07.1.8 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.8081.5596 [GMT 2:00]
Spuštěný z: c:\users\user\Downloads\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Phone\Skype.exe
c:\programdata\4812644201181863510
c:\programdata\4812644201181863510\07870b539a388c2b0006073755508bdd.ini
c:\programdata\4812644201181863510\1cbae057a4d1d4580006073755508bdd.ini
c:\programdata\4812644201181863510\25bedd18880898ff0006073755508bdd.ini
c:\programdata\4812644201181863510\2a0b23fa8d6e74d40006073755508bdd.ini
c:\programdata\4812644201181863510\465f8e59c1c2d7740006073755508bdd.ini
c:\programdata\4812644201181863510\48b7d16c1455ab250006073755508bdd.ini
c:\programdata\4812644201181863510\4ab07dd0adbafc360006073755508bdd.ini
c:\programdata\4812644201181863510\62dd3921369ec2f60006073755508bdd.ini
c:\programdata\4812644201181863510\7f34a1ce87ee8a850006073755508bdd.ini
c:\programdata\4812644201181863510\8c84dcdc46445dd60006073755508bdd.ini
c:\programdata\4812644201181863510\c17d33934423380b0006073755508bdd.ini
c:\programdata\4812644201181863510\cd5b15e575e1c3d00006073755508bdd.ini
c:\programdata\4812644201181863510\f6f6eb7fa6ec98570006073755508bdd.ini
c:\users\user\AppData\Local\.#
c:\users\user\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\directx.sys
c:\windows\msdownld.tmp
c:\windows\SysWow64\DEBUG.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-06-11 do 2015-07-11 )))))))))))))))))))))))))))))))
.
.
2015-07-11 20:59 . 2015-07-11 20:59 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2015-07-11 20:59 . 2015-07-11 20:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-07-11 20:59 . 2015-07-11 20:59 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2015-07-11 10:10 . 2015-07-11 10:10 -------- d-----w- c:\users\user\AppData\Roaming\Avira
2015-07-11 10:08 . 2015-06-16 07:36 43576 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2015-07-11 10:08 . 2015-06-16 07:36 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2015-07-11 10:08 . 2015-06-16 07:36 132656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2015-07-11 10:08 . 2015-06-16 07:36 153256 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2015-07-11 10:05 . 2015-07-11 10:08 -------- d-----w- c:\programdata\Avira
2015-07-11 10:05 . 2015-07-11 10:08 -------- d-----w- c:\program files (x86)\Avira
2015-07-11 09:17 . 2015-07-11 09:17 -------- d-----w- c:\users\user\Tracing
2015-07-10 18:24 . 2015-07-10 18:24 -------- d-----w- c:\program files (x86)\Battle.net
2015-07-10 16:08 . 2015-07-10 17:58 -------- d-----w- c:\users\user\AppData\Roaming\GameRanger
2015-06-27 20:37 . 2015-07-10 19:11 -------- d-----w- c:\users\user\AppData\Roaming\Trine2
2015-06-24 11:49 . 2015-06-24 11:49 -------- d-----w- c:\programdata\Battle.net
2015-06-22 19:45 . 2015-06-22 19:46 -------- d-----w- c:\program files (x86)\The KMPlayer
2015-06-22 18:18 . 2015-06-22 18:18 -------- d-----w- c:\users\user\AppData\Local\GHISLER
2015-06-22 18:18 . 2015-06-22 18:18 -------- d-----w- c:\users\user\AppData\Roaming\GHISLER
2015-06-22 18:15 . 2015-06-24 11:23 -------- d-----w- c:\program files (x86)\VS Revo Group
2015-06-22 17:58 . 2015-06-22 17:58 -------- d-----w- c:\program files (x86)\Alcohol Soft
2015-06-22 17:54 . 2015-06-22 17:54 868848 ----a-w- c:\windows\system32\drivers\sptd.sys
2015-06-22 17:52 . 2015-06-22 17:52 -------- d-----w- c:\program files (x86)\Franzis
2015-06-21 22:04 . 2015-06-22 19:04 -------- d-----w- c:\users\user\AppData\Roaming\Thinstall
2015-06-21 22:04 . 2015-06-21 22:04 -------- d-----w- c:\users\user\AppData\Local\Thinstall
2015-06-21 11:04 . 2015-06-21 11:04 -------- d-----w- c:\programdata\Steam
2015-06-17 10:43 . 2015-06-24 10:45 -------- d-----w- c:\programdata\{a5171ff4-18db-4ebe-a517-71ff418d7fd0}
2015-06-13 14:32 . 2015-07-02 19:59 -------- d-----w- c:\users\user\AppData\Roaming\TS3Client
2015-06-13 14:32 . 2015-06-13 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2015-06-13 08:00 . 2015-06-24 11:21 -------- d-----w- c:\program files\Common Files\AV
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-11 21:03 . 2015-02-12 20:13 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-07-05 04:42 . 2014-11-27 20:39 269992 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10248.bin
2015-06-18 06:42 . 2015-02-12 20:13 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-06-18 06:41 . 2015-02-12 20:13 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-06-18 06:41 . 2015-02-12 20:13 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-06-12 08:43 . 2014-11-18 06:39 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2015-04-29 22:01 . 2015-04-29 22:01 23200 ----a-w- c:\windows\system32\drivers\wdcsam64.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2015-07-08 03:54 2426256 ----a-w- c:\program files (x86)\AVG Web TuneUp\4.1.4.948\AVG Web TuneUp.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-02-26 21:41 233128 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-02-26 21:41 233128 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-02-26 21:41 233128 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2014-04-20 09:17 683200 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-11-21 7063832]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2015-02-27 5583120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-09-12 56128]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" [2011-08-30 1517056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Super-Charger"="c:\program files (x86)\MSI\Super-Charger\Super-Charger.exe" [2012-05-23 502328]
"vProt"="c:\program files (x86)\AVG Web TuneUp\vprot.exe" [2015-07-08 3174800]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2014-06-24 4101576]
"Avira Systray"="c:\program files (x86)\Avira\Launcher\Avira.Systray.exe" [2015-06-02 134368]
"avgnt"="c:\program files (x86)\Avira\Antivirus\avgnt.exe" [2015-06-16 730416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 AntiVirMailService;Avira Mail Protection;c:\program files (x86)\Avira\Antivirus\avmailc7.exe;c:\program files (x86)\Avira\Antivirus\avmailc7.exe [x]
R2 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\Antivirus\avwebg7.exe;c:\program files (x86)\Avira\Antivirus\avwebg7.exe [x]
R2 c6a5f59a;RelayEdit;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [x]
R3 BRSptStub;BitRaider Mini-Support Service Stub Loader;c:\programdata\BitRaider\BRSptStub.exe;c:\programdata\BitRaider\BRSptStub.exe [x]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe [x]
R3 ipadtst;ipadtst;c:\program files (x86)\MSI\Super-Charger\ipadtst_64.sys;c:\program files (x86)\MSI\Super-Charger\ipadtst_64.sys [x]
R3 Ke2200;NDIS Miniport Driver for the Killer e2200 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\e22w8x64.sys;c:\windows\SYSNATIVE\DRIVERS\e22w8x64.sys [x]
R3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\System32\drivers\wdcsam64.sys;c:\windows\SYSNATIVE\drivers\wdcsam64.sys [x]
R3 xusb22;Služba ovladače bezdrátového přijímače Xbox 360, 22;c:\windows\System32\drivers\xusb22.sys;c:\windows\SYSNATIVE\drivers\xusb22.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\Antivirus\sched.exe;c:\program files (x86)\Avira\Antivirus\sched.exe [x]
S2 Avira.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 Micro Star SCM;Micro Star SCM;c:\program files (x86)\SCM\MSIService.exe;c:\program files (x86)\SCM\MSIService.exe [x]
S2 MSI_SuperCharger;MSI_SuperCharger;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe [x]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vToolbarUpdater18.7.0;vToolbarUpdater18.7.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe [x]
S2 WtuSystemSupport;WtuSystemSupport;c:\program files (x86)\AVG Web TuneUp\WtuSystemSupport.exe;c:\program files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\System32\drivers\dtlitescsibus.sys;c:\windows\SYSNATIVE\drivers\dtlitescsibus.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 NETwNe64;@oem4.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;c:\windows\system32\DRIVERS\NETwew00.sys;c:\windows\SYSNATIVE\DRIVERS\NETwew00.sys [x]
S3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-02-26 21:41 260776 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-02-26 21:41 260776 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-02-26 21:41 260776 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2014-04-20 09:17 803520 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-27 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-27 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-11-27 441152]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-11-27 13192848]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2012-08-27 11577216]
"Radio Manager"="c:\program files (x86)\SCM\Radio Manager.exe" [2012-09-13 403848]
"SCM"="c:\program files (x86)\SCM\SCM.exe" [2012-09-13 399776]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2010-09-14 25600]
"Classic Start Menu"="c:\program files\Classic Shell\ClassicStartMenu.exe" [2014-04-20 161984]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://mysearch.avg.com/?cid={991B480E ... 2014-11-24 18:48&v=4.1.0.411&pid=wtu&sg=&sap=hp
mDefault_Search_URL = www.google.com
mDefault_Page_URL = www.google.com
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = www.google.com
IE: Odeslat do Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.2.0\ViProtocol.dll
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2nsbnboc.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxps://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-uTorrent - c:\users\user\AppData\Roaming\uTorrent\uTorrent.exe
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ike Ike! Nekketsu Hockey Bu - Subette Koronde Dai Rantou.lnk - c:\programdata\{c4ee3e10-6c59-b865-c4ee-e3e106c5f841}\Ike Ike! Nekketsu Hockey Bu - Subette Koronde Dai Rantou.exe --startup=1
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokemon FireRed.lnk - c:\programdata\{9864b5c8-0a48-dab8-9864-4b5c80a4d720}\Pokemon FireRed.exe --startup=1
Notify-SDWinLogon - SDWinLogon.dll
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-pcsx2-r5875 - d:\pcsx2 1.2.1\Uninst-pcsx2-r5875.exe
AddRemove-Uplay - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
AddRemove-uTorrent - c:\users\user\AppData\Roaming\uTorrent\uTorrent.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Avira\Antivirus\avguard.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\loggingserver.exe
c:\program files (x86)\AVG Web TuneUp\avgcefrend.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2015-07-11 23:08:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-07-11 21:08
.
Před spuštěním: 270 114 082 816 bytes free
Po spuštění: 269 821 632 512 bytes free
.
- - End Of File - - 6CF12F888FC0B9AA95E5AC9757B90158
objevila se mi v PC potvora Neshta. Kamarád mi doporučil ComboFix.
Neshta se mi stále objevuje, již sem odinstaloval Spybot. Používám antivir Avira.
Zde přikládám log z ComboFixu,
děkuji moc za kontrolu..
***********************************************************************************************************************
ComboFix 15-07-10.01 - user . 07. 2015 22:52:07.1.8 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.8081.5596 [GMT 2:00]
Spuštěný z: c:\users\user\Downloads\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Phone\Skype.exe
c:\programdata\4812644201181863510
c:\programdata\4812644201181863510\07870b539a388c2b0006073755508bdd.ini
c:\programdata\4812644201181863510\1cbae057a4d1d4580006073755508bdd.ini
c:\programdata\4812644201181863510\25bedd18880898ff0006073755508bdd.ini
c:\programdata\4812644201181863510\2a0b23fa8d6e74d40006073755508bdd.ini
c:\programdata\4812644201181863510\465f8e59c1c2d7740006073755508bdd.ini
c:\programdata\4812644201181863510\48b7d16c1455ab250006073755508bdd.ini
c:\programdata\4812644201181863510\4ab07dd0adbafc360006073755508bdd.ini
c:\programdata\4812644201181863510\62dd3921369ec2f60006073755508bdd.ini
c:\programdata\4812644201181863510\7f34a1ce87ee8a850006073755508bdd.ini
c:\programdata\4812644201181863510\8c84dcdc46445dd60006073755508bdd.ini
c:\programdata\4812644201181863510\c17d33934423380b0006073755508bdd.ini
c:\programdata\4812644201181863510\cd5b15e575e1c3d00006073755508bdd.ini
c:\programdata\4812644201181863510\f6f6eb7fa6ec98570006073755508bdd.ini
c:\users\user\AppData\Local\.#
c:\users\user\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\directx.sys
c:\windows\msdownld.tmp
c:\windows\SysWow64\DEBUG.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-06-11 do 2015-07-11 )))))))))))))))))))))))))))))))
.
.
2015-07-11 20:59 . 2015-07-11 20:59 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2015-07-11 20:59 . 2015-07-11 20:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-07-11 20:59 . 2015-07-11 20:59 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2015-07-11 10:10 . 2015-07-11 10:10 -------- d-----w- c:\users\user\AppData\Roaming\Avira
2015-07-11 10:08 . 2015-06-16 07:36 43576 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2015-07-11 10:08 . 2015-06-16 07:36 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2015-07-11 10:08 . 2015-06-16 07:36 132656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2015-07-11 10:08 . 2015-06-16 07:36 153256 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2015-07-11 10:05 . 2015-07-11 10:08 -------- d-----w- c:\programdata\Avira
2015-07-11 10:05 . 2015-07-11 10:08 -------- d-----w- c:\program files (x86)\Avira
2015-07-11 09:17 . 2015-07-11 09:17 -------- d-----w- c:\users\user\Tracing
2015-07-10 18:24 . 2015-07-10 18:24 -------- d-----w- c:\program files (x86)\Battle.net
2015-07-10 16:08 . 2015-07-10 17:58 -------- d-----w- c:\users\user\AppData\Roaming\GameRanger
2015-06-27 20:37 . 2015-07-10 19:11 -------- d-----w- c:\users\user\AppData\Roaming\Trine2
2015-06-24 11:49 . 2015-06-24 11:49 -------- d-----w- c:\programdata\Battle.net
2015-06-22 19:45 . 2015-06-22 19:46 -------- d-----w- c:\program files (x86)\The KMPlayer
2015-06-22 18:18 . 2015-06-22 18:18 -------- d-----w- c:\users\user\AppData\Local\GHISLER
2015-06-22 18:18 . 2015-06-22 18:18 -------- d-----w- c:\users\user\AppData\Roaming\GHISLER
2015-06-22 18:15 . 2015-06-24 11:23 -------- d-----w- c:\program files (x86)\VS Revo Group
2015-06-22 17:58 . 2015-06-22 17:58 -------- d-----w- c:\program files (x86)\Alcohol Soft
2015-06-22 17:54 . 2015-06-22 17:54 868848 ----a-w- c:\windows\system32\drivers\sptd.sys
2015-06-22 17:52 . 2015-06-22 17:52 -------- d-----w- c:\program files (x86)\Franzis
2015-06-21 22:04 . 2015-06-22 19:04 -------- d-----w- c:\users\user\AppData\Roaming\Thinstall
2015-06-21 22:04 . 2015-06-21 22:04 -------- d-----w- c:\users\user\AppData\Local\Thinstall
2015-06-21 11:04 . 2015-06-21 11:04 -------- d-----w- c:\programdata\Steam
2015-06-17 10:43 . 2015-06-24 10:45 -------- d-----w- c:\programdata\{a5171ff4-18db-4ebe-a517-71ff418d7fd0}
2015-06-13 14:32 . 2015-07-02 19:59 -------- d-----w- c:\users\user\AppData\Roaming\TS3Client
2015-06-13 14:32 . 2015-06-13 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2015-06-13 08:00 . 2015-06-24 11:21 -------- d-----w- c:\program files\Common Files\AV
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-11 21:03 . 2015-02-12 20:13 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-07-05 04:42 . 2014-11-27 20:39 269992 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10248.bin
2015-06-18 06:42 . 2015-02-12 20:13 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-06-18 06:41 . 2015-02-12 20:13 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-06-18 06:41 . 2015-02-12 20:13 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-06-12 08:43 . 2014-11-18 06:39 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2015-04-29 22:01 . 2015-04-29 22:01 23200 ----a-w- c:\windows\system32\drivers\wdcsam64.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2015-07-08 03:54 2426256 ----a-w- c:\program files (x86)\AVG Web TuneUp\4.1.4.948\AVG Web TuneUp.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-02-26 21:41 233128 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-02-26 21:41 233128 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-02-26 21:41 233128 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2014-04-20 09:17 683200 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-11-21 7063832]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2015-02-27 5583120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-09-12 56128]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" [2011-08-30 1517056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Super-Charger"="c:\program files (x86)\MSI\Super-Charger\Super-Charger.exe" [2012-05-23 502328]
"vProt"="c:\program files (x86)\AVG Web TuneUp\vprot.exe" [2015-07-08 3174800]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2014-06-24 4101576]
"Avira Systray"="c:\program files (x86)\Avira\Launcher\Avira.Systray.exe" [2015-06-02 134368]
"avgnt"="c:\program files (x86)\Avira\Antivirus\avgnt.exe" [2015-06-16 730416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 AntiVirMailService;Avira Mail Protection;c:\program files (x86)\Avira\Antivirus\avmailc7.exe;c:\program files (x86)\Avira\Antivirus\avmailc7.exe [x]
R2 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\Antivirus\avwebg7.exe;c:\program files (x86)\Avira\Antivirus\avwebg7.exe [x]
R2 c6a5f59a;RelayEdit;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [x]
R3 BRSptStub;BitRaider Mini-Support Service Stub Loader;c:\programdata\BitRaider\BRSptStub.exe;c:\programdata\BitRaider\BRSptStub.exe [x]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe [x]
R3 ipadtst;ipadtst;c:\program files (x86)\MSI\Super-Charger\ipadtst_64.sys;c:\program files (x86)\MSI\Super-Charger\ipadtst_64.sys [x]
R3 Ke2200;NDIS Miniport Driver for the Killer e2200 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\e22w8x64.sys;c:\windows\SYSNATIVE\DRIVERS\e22w8x64.sys [x]
R3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\System32\drivers\wdcsam64.sys;c:\windows\SYSNATIVE\drivers\wdcsam64.sys [x]
R3 xusb22;Služba ovladače bezdrátového přijímače Xbox 360, 22;c:\windows\System32\drivers\xusb22.sys;c:\windows\SYSNATIVE\drivers\xusb22.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\Antivirus\sched.exe;c:\program files (x86)\Avira\Antivirus\sched.exe [x]
S2 Avira.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 Micro Star SCM;Micro Star SCM;c:\program files (x86)\SCM\MSIService.exe;c:\program files (x86)\SCM\MSIService.exe [x]
S2 MSI_SuperCharger;MSI_SuperCharger;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe [x]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vToolbarUpdater18.7.0;vToolbarUpdater18.7.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe [x]
S2 WtuSystemSupport;WtuSystemSupport;c:\program files (x86)\AVG Web TuneUp\WtuSystemSupport.exe;c:\program files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\System32\drivers\dtlitescsibus.sys;c:\windows\SYSNATIVE\drivers\dtlitescsibus.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 NETwNe64;@oem4.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;c:\windows\system32\DRIVERS\NETwew00.sys;c:\windows\SYSNATIVE\DRIVERS\NETwew00.sys [x]
S3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-02-26 21:41 260776 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-02-26 21:41 260776 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-02-26 21:41 260776 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2014-04-20 09:17 803520 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-27 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-27 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-11-27 441152]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-11-27 13192848]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2012-08-27 11577216]
"Radio Manager"="c:\program files (x86)\SCM\Radio Manager.exe" [2012-09-13 403848]
"SCM"="c:\program files (x86)\SCM\SCM.exe" [2012-09-13 399776]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2010-09-14 25600]
"Classic Start Menu"="c:\program files\Classic Shell\ClassicStartMenu.exe" [2014-04-20 161984]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://mysearch.avg.com/?cid={991B480E ... 2014-11-24 18:48&v=4.1.0.411&pid=wtu&sg=&sap=hp
mDefault_Search_URL = www.google.com
mDefault_Page_URL = www.google.com
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = www.google.com
IE: Odeslat do Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.2.0\ViProtocol.dll
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2nsbnboc.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxps://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-uTorrent - c:\users\user\AppData\Roaming\uTorrent\uTorrent.exe
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ike Ike! Nekketsu Hockey Bu - Subette Koronde Dai Rantou.lnk - c:\programdata\{c4ee3e10-6c59-b865-c4ee-e3e106c5f841}\Ike Ike! Nekketsu Hockey Bu - Subette Koronde Dai Rantou.exe --startup=1
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokemon FireRed.lnk - c:\programdata\{9864b5c8-0a48-dab8-9864-4b5c80a4d720}\Pokemon FireRed.exe --startup=1
Notify-SDWinLogon - SDWinLogon.dll
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-pcsx2-r5875 - d:\pcsx2 1.2.1\Uninst-pcsx2-r5875.exe
AddRemove-Uplay - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
AddRemove-uTorrent - c:\users\user\AppData\Roaming\uTorrent\uTorrent.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Avira\Antivirus\avguard.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\loggingserver.exe
c:\program files (x86)\AVG Web TuneUp\avgcefrend.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2015-07-11 23:08:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-07-11 21:08
.
Před spuštěním: 270 114 082 816 bytes free
Po spuštění: 269 821 632 512 bytes free
.
- - End Of File - - 6CF12F888FC0B9AA95E5AC9757B90158

