
ComboFix 12-03-17.01 - MASTER 20.03.2012 16:52:41.4.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8172.5606 [GMT 1:00]
Spuštěný z: c:\users\MASTER\Desktop\ComboFixx.exe
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-20 do 2012-03-20 )))))))))))))))))))))))))))))))
.
.
2012-03-20 15:55 . 2012-03-20 15:55 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-03-20 15:55 . 2012-03-20 15:55 -------- d-----w- c:\users\mamka\AppData\Local\temp
2012-03-20 15:55 . 2012-03-20 15:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-20 14:33 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{870E2C4F-438C-418E-AEF4-971A688DD2F8}\mpengine.dll
2012-03-19 21:09 . 2012-03-19 22:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-03-19 21:09 . 2012-03-19 21:09 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-03-19 19:45 . 2012-03-19 19:46 -------- d-----w- c:\programdata\ConMet
2012-03-19 19:45 . 2012-03-19 19:45 -------- d-----w- c:\users\MASTER\AppData\Roaming\ConMet
2012-03-19 18:57 . 2012-03-19 18:57 -------- d-----w- c:\users\MASTER\AppData\Local\Mumble
2012-03-19 15:13 . 2012-03-19 15:14 -------- d-----w- C:\rsit
2012-03-19 15:13 . 2012-03-19 15:13 -------- d-----w- c:\program files\trend micro
2012-03-18 22:40 . 2012-03-18 22:40 -------- d-----w- C:\TDSSKiller_Quarantine
2012-03-16 23:15 . 2012-03-16 23:15 143360 ----a-w- c:\windows\SysWow64\UAService7.exe
2012-03-15 22:11 . 2011-11-19 15:20 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-15 22:11 . 2011-11-19 14:50 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-15 22:11 . 2011-11-19 14:50 3913584 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-15 22:07 . 2012-03-15 22:07 -------- d-----w- c:\users\UpdatusUser
2012-03-15 22:06 . 2012-02-29 20:59 2515790 ----a-w- c:\windows\system32\nvcoproc.bin
2012-03-15 20:29 . 2012-03-15 20:29 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-03-15 20:19 . 2012-02-03 04:34 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-03-15 20:19 . 2012-02-10 06:36 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-03-15 20:19 . 2012-02-10 05:38 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-03-15 20:16 . 2012-01-25 06:38 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-03-15 20:16 . 2012-01-25 06:38 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-15 20:16 . 2012-01-25 06:33 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-15 20:16 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-03-15 20:16 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-03-15 20:16 . 2012-02-17 04:58 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-15 20:16 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-05 17:14 . 2012-03-05 17:14 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
2012-02-29 12:26 . 2012-02-29 12:26 416064 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-02-28 17:57 . 2012-02-28 17:57 -------- d-----w- c:\users\MASTER\AppData\Local\Activision
2012-02-24 22:57 . 2012-02-24 22:57 -------- d-----w- c:\users\MASTER\AppData\Roaming\SPORE
2012-02-23 22:58 . 2004-03-08 22:00 124688 ----a-w- c:\windows\SysWow64\MSWINSCK.OCX
2012-02-23 22:58 . 2004-03-08 22:00 212240 ----a-w- c:\windows\SysWow64\RICHTX32.OCX
2012-02-23 22:58 . 2003-07-06 12:07 372736 ----a-w- c:\windows\SysWow64\IJL_11.DLL
2012-02-23 17:13 . 2012-02-23 17:13 -------- d-sh--w- c:\windows\ftpcache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-16 15:06 . 2011-08-16 09:58 197112 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-03-16 15:06 . 2011-08-18 19:43 345080 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-03-16 15:06 . 2011-08-16 09:58 345080 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-03-01 00:02 . 2011-08-18 19:43 7713088 ----a-w- c:\windows\SysWow64\nvwgf2um_evolve.dll
2012-03-01 00:02 . 2011-08-18 19:43 25543488 ----a-w- c:\windows\system32\nvoglv64_evolve.dll
2012-03-01 00:02 . 2011-08-18 19:43 19444544 ----a-w- c:\windows\SysWow64\nvoglv32_evolve.dll
2012-03-01 00:02 . 2011-08-18 19:43 17642816 ----a-w- c:\windows\system32\nvd3dumx_evolve.dll
2012-03-01 00:02 . 2011-08-18 19:43 1737536 ----a-w- c:\windows\system32\nvdispco64.dll
2012-03-01 00:02 . 2011-08-18 19:43 1466176 ----a-w- c:\windows\system32\nvgenco64.dll
2012-03-01 00:02 . 2011-08-16 09:58 9717568 ----a-w- c:\windows\system32\nvwgf2umx_evolve.dll
2012-03-01 00:02 . 2011-08-16 09:58 15009600 ----a-w- c:\windows\SysWow64\nvd3dum_evolve.dll
2012-03-01 00:02 . 2011-08-16 09:57 2660160 ----a-w- c:\windows\system32\nvapi64.dll
2012-03-01 00:02 . 2011-08-16 09:57 2301248 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-02-29 21:00 . 2011-01-07 18:49 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-02-29 21:00 . 2011-01-07 18:50 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-02-29 20:59 . 2011-01-07 18:49 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-02-29 20:59 . 2011-01-07 18:49 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-02-29 20:59 . 2011-01-07 18:49 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-02-29 20:59 . 2011-01-07 18:49 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-02-23 08:18 . 2011-08-17 08:46 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-02-16 17:57 . 2012-02-16 17:57 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2012-02-12 11:20 . 2011-08-30 13:30 314360 ----a-w- c:\windows\system32\EvoDisplayHelper.dll
2012-02-12 11:20 . 2011-08-30 13:30 197112 ----a-w- c:\windows\SysWow64\EvoDisplayHelper.dll
2012-01-28 11:52 . 2011-08-18 05:37 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-04 10:44 . 2012-02-15 15:23 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-01-04 08:58 . 2012-02-15 15:23 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2011-12-30 06:26 . 2012-02-15 15:22 515584 ----a-w- c:\windows\system32\timedate.cpl
2011-12-30 05:27 . 2012-02-15 15:22 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2011-12-28 03:59 . 2012-02-15 15:22 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2011-12-25 14:34 . 2011-12-25 14:34 65536 ----a-r- c:\users\MASTER\AppData\Roaming\Microsoft\Installer\{0CE1A6C0-F3F7-49E6-8F9D-2431F9827441}\NewShortcut5_0CE1A6C0F3F749E68F9D2431F9827441.exe
2011-12-25 14:34 . 2011-12-25 14:34 65536 ----a-r- c:\users\MASTER\AppData\Roaming\Microsoft\Installer\{0CE1A6C0-F3F7-49E6-8F9D-2431F9827441}\NewShortcut4_0CE1A6C0F3F749E68F9D2431F9827441.exe
2011-12-25 14:34 . 2011-12-25 14:34 65536 ----a-r- c:\users\MASTER\AppData\Roaming\Microsoft\Installer\{0CE1A6C0-F3F7-49E6-8F9D-2431F9827441}\NewShortcut3_0CE1A6C0F3F749E68F9D2431F9827441.exe
2011-12-25 14:34 . 2011-12-25 14:34 65536 ----a-r- c:\users\MASTER\AppData\Roaming\Microsoft\Installer\{0CE1A6C0-F3F7-49E6-8F9D-2431F9827441}\NewShortcut2_0CE1A6C0F3F749E68F9D2431F9827441.exe
2011-12-25 14:31 . 2011-12-25 14:31 3584 ----a-r- c:\users\MASTER\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
.
.
((((((((((((((((((((((((((((( SnapShot_2012-03-18_21.37.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-03-19 17:45 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-03-15 20:25 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-03-15 20:25 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-03-19 17:45 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-03-19 17:45 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-03-15 20:25 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-08-16 09:47 . 2012-03-20 14:34 42080 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-03-20 14:34 29170 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-08-15 20:21 . 2012-03-20 14:34 11052 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-99504729-2130033436-3414475424-1000_UserData.bin
+ 2011-08-15 20:17 . 2012-03-20 14:54 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-08-15 20:17 . 2012-03-06 14:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-08-15 20:17 . 2012-03-06 14:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-03-20 14:54 . 2012-03-20 14:54 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-03-06 14:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-03-20 14:54 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-08-18 19:45 . 2012-03-19 20:48 11222 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\qwavecache.dat
+ 2011-08-18 17:35 . 2012-03-19 14:41 9560 c:\windows\system32\NetworkList\Icons\{CD035DDF-3555-4815-A791-1ACB7D64D37E}_48.bin
- 2011-08-18 17:35 . 2012-02-16 16:42 9560 c:\windows\system32\NetworkList\Icons\{CD035DDF-3555-4815-A791-1ACB7D64D37E}_48.bin
+ 2011-08-18 17:35 . 2012-03-19 14:41 4280 c:\windows\system32\NetworkList\Icons\{CD035DDF-3555-4815-A791-1ACB7D64D37E}_32.bin
- 2011-08-18 17:35 . 2012-02-16 16:42 4280 c:\windows\system32\NetworkList\Icons\{CD035DDF-3555-4815-A791-1ACB7D64D37E}_32.bin
- 2011-08-18 17:35 . 2012-02-16 16:42 2456 c:\windows\system32\NetworkList\Icons\{CD035DDF-3555-4815-A791-1ACB7D64D37E}_24.bin
+ 2011-08-18 17:35 . 2012-03-19 14:41 2456 c:\windows\system32\NetworkList\Icons\{CD035DDF-3555-4815-A791-1ACB7D64D37E}_24.bin
+ 2011-11-27 14:50 . 2012-03-19 14:43 9560 c:\windows\system32\NetworkList\Icons\{BE99F217-CA18-4083-A765-2C9822B4C04B}_48.bin
- 2011-11-27 14:50 . 2011-11-27 14:50 9560 c:\windows\system32\NetworkList\Icons\{BE99F217-CA18-4083-A765-2C9822B4C04B}_48.bin
+ 2011-11-27 14:50 . 2012-03-19 14:43 4280 c:\windows\system32\NetworkList\Icons\{BE99F217-CA18-4083-A765-2C9822B4C04B}_32.bin
- 2011-11-27 14:50 . 2011-11-27 14:50 4280 c:\windows\system32\NetworkList\Icons\{BE99F217-CA18-4083-A765-2C9822B4C04B}_32.bin
- 2011-11-27 14:50 . 2011-11-27 14:50 2456 c:\windows\system32\NetworkList\Icons\{BE99F217-CA18-4083-A765-2C9822B4C04B}_24.bin
+ 2011-11-27 14:50 . 2012-03-19 14:43 2456 c:\windows\system32\NetworkList\Icons\{BE99F217-CA18-4083-A765-2C9822B4C04B}_24.bin
- 2012-03-18 21:36 . 2012-03-18 21:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-03-20 15:55 . 2012-03-20 15:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-03-20 15:55 . 2012-03-20 15:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-03-18 21:36 . 2012-03-18 21:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-03-18 07:15 . 2010-03-18 07:15 770384 c:\windows\SysWOW64\msvcr100.dll
+ 2010-03-18 08:15 . 2010-03-18 08:15 770384 c:\windows\SysWOW64\msvcr100.dll
+ 2010-03-18 08:15 . 2010-03-18 08:15 421200 c:\windows\SysWOW64\msvcp100.dll
- 2010-03-18 07:15 . 2010-03-18 07:15 421200 c:\windows\SysWOW64\msvcp100.dll
+ 2011-08-16 12:13 . 2012-03-19 15:58 303674 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2009-07-14 05:12 . 2012-03-20 14:54 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 04:46 . 2012-03-19 13:53 105184 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-07-14 05:01 . 2012-03-20 15:55 395268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-03-18 21:35 395268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-08-16 05:18 . 2012-03-20 15:55 5265304 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-08-16 05:18 . 2012-03-18 21:35 5265304 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-08-16 04:40 . 2012-03-19 20:48 8770868 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-99504729-2130033436-3414475424-1000-8192.dat
+ 2011-08-16 05:12 . 2012-03-20 15:55 9480158 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-99504729-2130033436-3414475424-1000-12288.dat
+ 2012-03-19 19:03 . 2012-03-19 19:03 17904640 c:\windows\Installer\3d295.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-07-26 16:23 1493160 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-07-26 1493160]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"OscarEditor"="c:\program files (x86)\Anti-Vibrate Oscar Editor\OscarEditor.exe" [2009-12-22 2647040]
"Steam"="d:\steam\Steam.exe" [2011-12-14 1242448]
"EvolveClient"="c:\program files\Echobit\Evolve\EvolveClient.exe" [2012-02-22 1735672]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-02-22 740216]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" [2010-11-18 1351680]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\dragon age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
R3 GGSAFERDriver;GGSAFER Driver;c:\users\MASTER\Garena Classic\safedrv.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 EvoSvc;Evolve Service;c:\program files\Echobit\Evolve\EvoSvc.exe [2012-02-22 1459192]
S2 QipGuard;QipGuard;c:\program files (x86)\QipGuard\QipGuard.exe [2011-08-10 190336]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
S3 EvoKbFilter;Evolve Keyboard Filter Driver;c:\windows\system32\Drivers\EvoKbFilter.sys [x]
S3 EvolveVirtualAdapter;Evolve Virtual Miniport Driver;c:\windows\system32\DRIVERS\evolve.sys [x]
S3 EvoMouFilter;Evolve Mouse Filter Driver;c:\windows\system32\Drivers\EvoMouFilter.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-01-04 6602856]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
"THXCfg64"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://www.bigseekpro.com/bsprpc/{54AF5073-C9D ... 3D3AA7CF2B}
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-QipGuard - c:\users\MASTER\AppData\Roaming\QipGuard\QipGuard.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-99504729-2130033436-3414475424-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:c3,9c,dd,1d,8f,4b,f0,0e,c7,af,79,b3,89,9c,77,35,cc,47,7b,46,7e,d1,7a,
a5,4e,87,d3,36,f8,19,be,c4,d4,54,fb,97,ae,3d,25,71,d1,1f,d2,92,8b,13,8b,bc,\
"??"=hex:90,4c,53,40,5e,80,19,01,24,59,4b,71,fa,9f,60,c0
.
[HKEY_USERS\S-1-5-21-99504729-2130033436-3414475424-1000\Software\SecuROM\License information*]
"datasecu"=hex:5f,18,79,47,6b,39,cd,13,5c,c7,6c,fc,e5,70,f8,84,be,3a,ab,44,73,
6d,c4,7f,6b,8e,f4,ad,38,80,d4,70,85,d8,0c,bb,c3,a6,47,06,1e,18,b8,07,aa,d1,\
"rkeysecu"=hex:6b,3b,2e,1b,35,ba,64,a6,4e,81,14,c4,a9,8b,e2,db
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\UAService7.exe
c:\program files (x86)\Opera\opera.exe
.
**************************************************************************
.
Celkový čas: 2012-03-20 16:58:42 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-03-20 15:58
ComboFix2.txt 2012-03-19 20:51
ComboFix3.txt 2012-03-18 21:39
ComboFix4.txt 2012-02-12 12:44
.
Před spuštěním: Volných bajtů: 136 364 892 160
Po spuštění: Volných bajtů: 136 275 353 600
.
- - End Of File - - 625CF4FE68FD52262BCB9E2D4F2C8F8A