
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Win64: Rootkit-gen
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Win64: Rootkit-gen
Dobrý den,
Avast mi hlásí Win64: Rootkit-gen. V počítači se mi (i po manuálním vymazání) opakovaně objevuje složka msupdate71 s tímto Rootkitem. Avast s tím není schopen nic udělat, CCleaner ho ani nehlásí... nedaří se ho zlikvidovat. Prosím o velmi polopatický návod co mám dělat. Díky!
Přikládám log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Slimaca at 2014-09-02 10:42:15
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 26 GB (34%) free of 76 GB
Total RAM: 3327 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:42:17, on 2.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Philips Display\SmartControl\DTHtml.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Portrait Displays\Pivot Pro Plugin\wpctrl.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Portrait Displays\Pivot Pro Plugin\floater.exe
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\System32\rundll32.exe
C:\Users\Slimaca\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Stažené\RSIT.exe
C:\Program Files\trend micro\Slimaca.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: pcvpravo 192.168.1.10
O1 - Hosts: mlazik-msi 192.168.1.110
O1 - Hosts: pcvlevo 192.168.1.11
O1 - Hosts: hpd18d53 192.168.1.2
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" -delay=10
O4 - HKLM\..\Run: [DT PLP] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -PLP
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [tsiVideo] rundll32.exe C:\Users\Slimaca\AppData\Local\Temp\\mdi064.dll,asdasd
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
O17 - HKLM\System\CS1\Services\Tcpip\..\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
O17 - HKLM\System\CS2\Services\Tcpip\..\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 10168 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "keyword.URL" - "https://www.google.com/search"
"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_179.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\extensions\
plugin@getwebcake.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\searchplugins\
firmycz.xml
Google.xml
mapycz.xml
zbocz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2010-05-28 328248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-08-06 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-13 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-08-06 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2010-05-28 517688]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe [2001-07-09 155648]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2012-03-27 10967656]
"PivotSoftware"=C:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [2010-05-13 110192]
"DT PLP"=C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe [2010-05-17 121456]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2012-09-13 1009288]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2011-03-14 2565520]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"=C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2011-01-15 452016]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-29 4085896]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"=C:\Users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe [2012-09-13 1009288]
"cz.seznam.software.szndesktop"=C:\Users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-01-22 92152]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-24 21650016]
"tsiVideo"=C:\Users\Slimaca\AppData\Local\Temp\\mdi064.dll [2014-08-31 1288192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.tscc"=tsccvid.dll
"VIDC.FPS1"=frapsvid.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-02 07:13:59 ----D---- C:\rsit
2014-09-02 07:13:59 ----D---- C:\Program Files\trend micro
2014-09-01 21:59:28 ----D---- C:\ProgramData\Malwarebytes
2014-09-01 21:59:16 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-01 21:59:16 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 21:58:15 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-09-01 17:36:54 ----D---- C:\Program Files\CCleaner
2014-09-01 17:35:48 ----D---- C:\Program Files\Sophos
2014-08-31 17:04:24 ----D---- C:\Program Files\SGP Systems
2014-08-31 17:02:59 ----A---- C:\Windows\BALTIE.INI
2014-08-28 12:43:32 ----A---- C:\Windows\system32\win32k.sys
2014-08-28 12:43:31 ----A---- C:\Windows\system32\gdi32.dll
2014-08-23 13:36:19 ----D---- C:\Program Files\Common Files\Skype
2014-08-14 03:06:00 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-14 03:05:56 ----A---- C:\Windows\system32\icardres.dll
2014-08-14 03:05:50 ----A---- C:\Windows\system32\icardagt.exe
2014-08-14 03:05:46 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 20:05:54 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-13 20:05:27 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-08-13 20:05:27 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 20:05:26 ----A---- C:\Windows\system32\cdd.dll
2014-08-13 20:05:19 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 20:05:19 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 20:05:19 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-13 20:05:18 ----A---- C:\Windows\system32\urlmon.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 20:05:18 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-13 20:05:18 ----A---- C:\Windows\system32\iernonce.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-13 20:05:17 ----A---- C:\Windows\system32\msrating.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\vbscript.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\iesetup.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-13 20:05:15 ----A---- C:\Windows\system32\wininet.dll
2014-08-13 20:05:14 ----A---- C:\Windows\system32\ieui.dll
2014-08-13 20:05:14 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-13 20:05:13 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-13 20:05:13 ----A---- C:\Windows\system32\ieframe.dll
2014-08-13 20:05:12 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-08-13 20:05:12 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-13 20:05:11 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-13 20:05:11 ----A---- C:\Windows\system32\iertutil.dll
2014-08-13 20:05:10 ----A---- C:\Windows\system32\mshtml.dll
2014-08-13 20:05:10 ----A---- C:\Windows\system32\jscript9.dll
2014-08-13 20:03:54 ----A---- C:\Windows\system32\tzres.dll
2014-08-13 20:03:28 ----A---- C:\Windows\system32\msi.dll
2014-08-13 20:03:27 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 20:03:27 ----A---- C:\Windows\system32\consent.exe
2014-08-13 20:03:27 ----A---- C:\Windows\system32\authui.dll
2014-08-13 20:02:47 ----A---- C:\Windows\system32\aepdu.dll
2014-08-13 20:02:47 ----A---- C:\Windows\system32\aeinv.dll
2014-08-13 20:02:20 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-06 20:08:36 ----D---- C:\Users\Slimaca\AppData\Roaming\Oracle
2014-08-06 20:08:00 ----D---- C:\Program Files\Common Files\Java
2014-08-06 20:07:52 ----A---- C:\Windows\system32\javaws.exe
2014-08-06 20:07:47 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2014-08-06 20:07:47 ----A---- C:\Windows\system32\javaw.exe
2014-08-06 20:07:47 ----A---- C:\Windows\system32\java.exe
======List of files/folders modified in the last 1 month======
2014-09-02 10:42:17 ----D---- C:\Windows\Temp
2014-09-02 10:28:36 ----D---- C:\Users\Slimaca\AppData\Roaming\Skype
2014-09-02 07:19:57 ----D---- C:\Windows
2014-09-02 07:19:57 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-09-02 07:14:18 ----D---- C:\Users\Slimaca\AppData\Roaming\Seznam.cz
2014-09-02 07:13:59 ----D---- C:\Program Files
2014-09-02 07:08:14 ----D---- C:\ProgramData\NVIDIA
2014-09-02 06:53:47 ----D---- C:\Windows\system32\config
2014-09-02 00:55:05 ----D---- C:\Windows\System32
2014-09-01 23:45:57 ----D---- C:\Windows\inf
2014-09-01 22:16:32 ----D---- C:\Windows\system32\drivers
2014-09-01 22:14:13 ----SHD---- C:\System Volume Information
2014-09-01 21:59:28 ----HD---- C:\ProgramData
2014-09-01 21:49:20 ----D---- C:\Windows\Prefetch
2014-09-01 17:40:29 ----D---- C:\Users\Slimaca\AppData\Roaming\DAEMON Tools Lite
2014-09-01 17:40:26 ----D---- C:\Users\Slimaca\AppData\Roaming\uTorrent
2014-09-01 17:40:26 ----D---- C:\Program Files\PDFCreator
2014-09-01 17:40:25 ----D---- C:\ProgramData\BlueStacksSetup
2014-09-01 17:40:22 ----D---- C:\Windows\Panther
2014-09-01 17:40:16 ----D---- C:\Windows\Logs
2014-09-01 17:40:15 ----D---- C:\Windows\debug
2014-09-01 17:37:00 ----D---- C:\Windows\system32\Tasks
2014-09-01 17:35:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-08-31 16:33:32 ----D---- C:\Users\Slimaca\AppData\Roaming\Adobe
2014-08-31 16:33:32 ----D---- C:\ProgramData\Adobe
2014-08-29 03:18:31 ----D---- C:\Windows\winsxs
2014-08-28 12:41:39 ----D---- C:\Windows\system32\catroot2
2014-08-28 12:41:39 ----D---- C:\Windows\system32\catroot
2014-08-28 12:30:53 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2014-08-23 13:36:23 ----SHD---- C:\Windows\Installer
2014-08-23 13:36:23 ----HD---- C:\Config.Msi
2014-08-23 13:36:23 ----D---- C:\ProgramData\Skype
2014-08-23 13:36:19 ----D---- C:\Program Files\Common Files
2014-08-22 20:44:22 ----D---- C:\Program Files\Battle.net
2014-08-21 19:52:16 ----D---- C:\Users\Slimaca\AppData\Roaming\.minecraft
2014-08-14 09:52:46 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-14 04:19:10 ----D---- C:\Windows\rescache
2014-08-14 03:39:39 ----D---- C:\Windows\Microsoft.NET
2014-08-14 03:38:56 ----RSD---- C:\Windows\assembly
2014-08-14 03:27:20 ----D---- C:\Windows\system32\en-US
2014-08-14 03:27:20 ----D---- C:\Windows\system32\cs-CZ
2014-08-14 03:27:20 ----D---- C:\Windows\PolicyDefinitions
2014-08-14 03:27:20 ----D---- C:\Windows\ehome
2014-08-14 03:27:19 ----D---- C:\Program Files\Internet Explorer
2014-08-14 03:27:18 ----SD---- C:\Windows\system32\CompatTel
2014-08-14 03:27:16 ----RSD---- C:\Windows\Fonts
2014-08-14 03:11:57 ----D---- C:\ProgramData\Microsoft Help
2014-08-14 03:11:46 ----D---- C:\Windows\system32\MRT
2014-08-14 03:09:05 ----A---- C:\Windows\system32\MRT.exe
2014-08-06 20:08:06 ----D---- C:\ProgramData\Oracle
2014-08-06 19:31:35 ----D---- C:\Windows\system32\NDF
2014-08-06 18:39:33 ----SD---- C:\ProgramData\Microsoft
2014-08-05 13:11:15 ----SD---- C:\Users\Slimaca\AppData\Roaming\Microsoft
2014-08-05 09:20:02 ----N---- C:\Windows\system32\MpSigStub.exe
2014-08-03 15:26:05 ----D---- C:\Program Files\Mozilla Maintenance Service
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-13 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-13 192352]
R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2012-05-16 210464]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-13 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-13 414520]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\Windows\system32\drivers\es1371mp.sys [2002-06-03 40832]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2012-03-27 3204200]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6232.sys [2012-05-16 287008]
R3 PdiPorts;Portrait Displays low level device driver; C:\Windows\System32\Drivers\PdiPorts.sys [2010-04-16 17136]
S3 ActivHidSerMini;Promethean Serial Board Driver; C:\Windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\Windows\system32\3AFC.tmp []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 prmvmouse;Promethean HID Mouse Service; C:\Windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 9216]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-13 50344]
R2 DTSRVC;Portrait Displays Display Tune Service; C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [2010-05-17 121456]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2009-04-19 387616]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2009-04-19 178720]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-18 639776]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 1713904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-26 1260320]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-14 262320]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-07-25 108032]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-07-30 119408]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-05-18 1343400]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Avast mi hlásí Win64: Rootkit-gen. V počítači se mi (i po manuálním vymazání) opakovaně objevuje složka msupdate71 s tímto Rootkitem. Avast s tím není schopen nic udělat, CCleaner ho ani nehlásí... nedaří se ho zlikvidovat. Prosím o velmi polopatický návod co mám dělat. Díky!
Přikládám log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Slimaca at 2014-09-02 10:42:15
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 26 GB (34%) free of 76 GB
Total RAM: 3327 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:42:17, on 2.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Philips Display\SmartControl\DTHtml.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Portrait Displays\Pivot Pro Plugin\wpctrl.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Portrait Displays\Pivot Pro Plugin\floater.exe
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\System32\rundll32.exe
C:\Users\Slimaca\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Stažené\RSIT.exe
C:\Program Files\trend micro\Slimaca.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: pcvpravo 192.168.1.10
O1 - Hosts: mlazik-msi 192.168.1.110
O1 - Hosts: pcvlevo 192.168.1.11
O1 - Hosts: hpd18d53 192.168.1.2
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" -delay=10
O4 - HKLM\..\Run: [DT PLP] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -PLP
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [tsiVideo] rundll32.exe C:\Users\Slimaca\AppData\Local\Temp\\mdi064.dll,asdasd
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
O17 - HKLM\System\CS1\Services\Tcpip\..\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
O17 - HKLM\System\CS2\Services\Tcpip\..\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 10168 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "keyword.URL" - "https://www.google.com/search"
"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_179.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\extensions\
plugin@getwebcake.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\searchplugins\
firmycz.xml
Google.xml
mapycz.xml
zbocz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2010-05-28 328248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-08-06 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-13 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-08-06 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2010-05-28 517688]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe [2001-07-09 155648]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2012-03-27 10967656]
"PivotSoftware"=C:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [2010-05-13 110192]
"DT PLP"=C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe [2010-05-17 121456]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2012-09-13 1009288]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2011-03-14 2565520]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"=C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2011-01-15 452016]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-29 4085896]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"=C:\Users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe [2012-09-13 1009288]
"cz.seznam.software.szndesktop"=C:\Users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-01-22 92152]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-24 21650016]
"tsiVideo"=C:\Users\Slimaca\AppData\Local\Temp\\mdi064.dll [2014-08-31 1288192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.tscc"=tsccvid.dll
"VIDC.FPS1"=frapsvid.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-02 07:13:59 ----D---- C:\rsit
2014-09-02 07:13:59 ----D---- C:\Program Files\trend micro
2014-09-01 21:59:28 ----D---- C:\ProgramData\Malwarebytes
2014-09-01 21:59:16 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-01 21:59:16 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 21:58:15 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-09-01 17:36:54 ----D---- C:\Program Files\CCleaner
2014-09-01 17:35:48 ----D---- C:\Program Files\Sophos
2014-08-31 17:04:24 ----D---- C:\Program Files\SGP Systems
2014-08-31 17:02:59 ----A---- C:\Windows\BALTIE.INI
2014-08-28 12:43:32 ----A---- C:\Windows\system32\win32k.sys
2014-08-28 12:43:31 ----A---- C:\Windows\system32\gdi32.dll
2014-08-23 13:36:19 ----D---- C:\Program Files\Common Files\Skype
2014-08-14 03:06:00 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-14 03:05:56 ----A---- C:\Windows\system32\icardres.dll
2014-08-14 03:05:50 ----A---- C:\Windows\system32\icardagt.exe
2014-08-14 03:05:46 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 20:05:54 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-13 20:05:27 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-08-13 20:05:27 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 20:05:26 ----A---- C:\Windows\system32\cdd.dll
2014-08-13 20:05:19 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 20:05:19 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 20:05:19 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-13 20:05:18 ----A---- C:\Windows\system32\urlmon.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 20:05:18 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-13 20:05:18 ----A---- C:\Windows\system32\iernonce.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-13 20:05:18 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-13 20:05:17 ----A---- C:\Windows\system32\msrating.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\vbscript.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\iesetup.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-13 20:05:16 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-13 20:05:15 ----A---- C:\Windows\system32\wininet.dll
2014-08-13 20:05:14 ----A---- C:\Windows\system32\ieui.dll
2014-08-13 20:05:14 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-13 20:05:13 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-13 20:05:13 ----A---- C:\Windows\system32\ieframe.dll
2014-08-13 20:05:12 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-08-13 20:05:12 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-13 20:05:11 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-13 20:05:11 ----A---- C:\Windows\system32\iertutil.dll
2014-08-13 20:05:10 ----A---- C:\Windows\system32\mshtml.dll
2014-08-13 20:05:10 ----A---- C:\Windows\system32\jscript9.dll
2014-08-13 20:03:54 ----A---- C:\Windows\system32\tzres.dll
2014-08-13 20:03:28 ----A---- C:\Windows\system32\msi.dll
2014-08-13 20:03:27 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 20:03:27 ----A---- C:\Windows\system32\consent.exe
2014-08-13 20:03:27 ----A---- C:\Windows\system32\authui.dll
2014-08-13 20:02:47 ----A---- C:\Windows\system32\aepdu.dll
2014-08-13 20:02:47 ----A---- C:\Windows\system32\aeinv.dll
2014-08-13 20:02:20 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 20:01:52 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-06 20:08:36 ----D---- C:\Users\Slimaca\AppData\Roaming\Oracle
2014-08-06 20:08:00 ----D---- C:\Program Files\Common Files\Java
2014-08-06 20:07:52 ----A---- C:\Windows\system32\javaws.exe
2014-08-06 20:07:47 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2014-08-06 20:07:47 ----A---- C:\Windows\system32\javaw.exe
2014-08-06 20:07:47 ----A---- C:\Windows\system32\java.exe
======List of files/folders modified in the last 1 month======
2014-09-02 10:42:17 ----D---- C:\Windows\Temp
2014-09-02 10:28:36 ----D---- C:\Users\Slimaca\AppData\Roaming\Skype
2014-09-02 07:19:57 ----D---- C:\Windows
2014-09-02 07:19:57 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-09-02 07:14:18 ----D---- C:\Users\Slimaca\AppData\Roaming\Seznam.cz
2014-09-02 07:13:59 ----D---- C:\Program Files
2014-09-02 07:08:14 ----D---- C:\ProgramData\NVIDIA
2014-09-02 06:53:47 ----D---- C:\Windows\system32\config
2014-09-02 00:55:05 ----D---- C:\Windows\System32
2014-09-01 23:45:57 ----D---- C:\Windows\inf
2014-09-01 22:16:32 ----D---- C:\Windows\system32\drivers
2014-09-01 22:14:13 ----SHD---- C:\System Volume Information
2014-09-01 21:59:28 ----HD---- C:\ProgramData
2014-09-01 21:49:20 ----D---- C:\Windows\Prefetch
2014-09-01 17:40:29 ----D---- C:\Users\Slimaca\AppData\Roaming\DAEMON Tools Lite
2014-09-01 17:40:26 ----D---- C:\Users\Slimaca\AppData\Roaming\uTorrent
2014-09-01 17:40:26 ----D---- C:\Program Files\PDFCreator
2014-09-01 17:40:25 ----D---- C:\ProgramData\BlueStacksSetup
2014-09-01 17:40:22 ----D---- C:\Windows\Panther
2014-09-01 17:40:16 ----D---- C:\Windows\Logs
2014-09-01 17:40:15 ----D---- C:\Windows\debug
2014-09-01 17:37:00 ----D---- C:\Windows\system32\Tasks
2014-09-01 17:35:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-08-31 16:33:32 ----D---- C:\Users\Slimaca\AppData\Roaming\Adobe
2014-08-31 16:33:32 ----D---- C:\ProgramData\Adobe
2014-08-29 03:18:31 ----D---- C:\Windows\winsxs
2014-08-28 12:41:39 ----D---- C:\Windows\system32\catroot2
2014-08-28 12:41:39 ----D---- C:\Windows\system32\catroot
2014-08-28 12:30:53 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2014-08-23 13:36:23 ----SHD---- C:\Windows\Installer
2014-08-23 13:36:23 ----HD---- C:\Config.Msi
2014-08-23 13:36:23 ----D---- C:\ProgramData\Skype
2014-08-23 13:36:19 ----D---- C:\Program Files\Common Files
2014-08-22 20:44:22 ----D---- C:\Program Files\Battle.net
2014-08-21 19:52:16 ----D---- C:\Users\Slimaca\AppData\Roaming\.minecraft
2014-08-14 09:52:46 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-14 04:19:10 ----D---- C:\Windows\rescache
2014-08-14 03:39:39 ----D---- C:\Windows\Microsoft.NET
2014-08-14 03:38:56 ----RSD---- C:\Windows\assembly
2014-08-14 03:27:20 ----D---- C:\Windows\system32\en-US
2014-08-14 03:27:20 ----D---- C:\Windows\system32\cs-CZ
2014-08-14 03:27:20 ----D---- C:\Windows\PolicyDefinitions
2014-08-14 03:27:20 ----D---- C:\Windows\ehome
2014-08-14 03:27:19 ----D---- C:\Program Files\Internet Explorer
2014-08-14 03:27:18 ----SD---- C:\Windows\system32\CompatTel
2014-08-14 03:27:16 ----RSD---- C:\Windows\Fonts
2014-08-14 03:11:57 ----D---- C:\ProgramData\Microsoft Help
2014-08-14 03:11:46 ----D---- C:\Windows\system32\MRT
2014-08-14 03:09:05 ----A---- C:\Windows\system32\MRT.exe
2014-08-06 20:08:06 ----D---- C:\ProgramData\Oracle
2014-08-06 19:31:35 ----D---- C:\Windows\system32\NDF
2014-08-06 18:39:33 ----SD---- C:\ProgramData\Microsoft
2014-08-05 13:11:15 ----SD---- C:\Users\Slimaca\AppData\Roaming\Microsoft
2014-08-05 09:20:02 ----N---- C:\Windows\system32\MpSigStub.exe
2014-08-03 15:26:05 ----D---- C:\Program Files\Mozilla Maintenance Service
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-13 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-13 192352]
R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2012-05-16 210464]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-13 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-13 414520]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\Windows\system32\drivers\es1371mp.sys [2002-06-03 40832]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2012-03-27 3204200]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6232.sys [2012-05-16 287008]
R3 PdiPorts;Portrait Displays low level device driver; C:\Windows\System32\Drivers\PdiPorts.sys [2010-04-16 17136]
S3 ActivHidSerMini;Promethean Serial Board Driver; C:\Windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\Windows\system32\3AFC.tmp []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 prmvmouse;Promethean HID Mouse Service; C:\Windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 9216]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-13 50344]
R2 DTSRVC;Portrait Displays Display Tune Service; C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [2010-05-17 121456]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2009-04-19 387616]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2009-04-19 178720]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-18 639776]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 1713904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-26 1260320]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-14 262320]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-07-25 108032]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-07-30 119408]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-05-18 1343400]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119544
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Win64: Rootkit-gen
Zdravím!
Spusťte tento program:
Spusťte tento program:
Stáhněte Malwarebytes Anti-Rootkit http://www.malwarebytes.org/products/mbar/
Uložte nejlépe na Plochu a rozbalte
Spusťte kliknutím na mbar
Nyní postupně klikněte na Next a Update
Po dokončení update (aktualizace) databáze klikněte opět na Next
Nechte zaškrtnute všechny tři možnosti a kliněte na Scan čímž spustíte prohledavani PC
Po dokončeni skenu (cca 5 minutek) zkontrolujte, zda-li je u všech nalezů (samozrejme pokud budou) zatržítko
Tež zkontrolujte, jestli je zatržitko u Create Restore point
Nyní klikněte na CleanUp čímž nalezenou infekci odstraníme
PC bude restartován
Složka mbar by měla obsahovat log (a zřejmě se i sám otevře) mbar-log-rok-měsíc-den (hodina-minuta-sekunda).txt, ten mi sem dejte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Win64: Rootkit-gen
Děkuji za pomoc.
Postupovala jsem svědomitě podle pokynů, ale scan byl ukončen hláškou, že nic nebylo nalezeno.
Posílám print screen, aby bylo vidět jak to u mě vypadá (i když v rozlišení max. 800x600 toho asi nebude moc vidět...).
Budu vděčná za další pokyny.
K.
Postupovala jsem svědomitě podle pokynů, ale scan byl ukončen hláškou, že nic nebylo nalezeno.
Posílám print screen, aby bylo vidět jak to u mě vypadá (i když v rozlišení max. 800x600 toho asi nebude moc vidět...).
Budu vděčná za další pokyny.
K.
- Přílohy
-
- Plocha
- PrtScr.jpg (233.64 KiB) Zobrazeno 2428 x
- Rudy
- Site Admin
- Příspěvky: 119544
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Win64: Rootkit-gen
Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se
jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine
aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,
pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k
nezadoucim kolizim s rezidentem antispyware.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Win64: Rootkit-gen
Tak to mě děsí - ComboFix po mě chce vypnutí Avastu a Avast je to jediný, co mi Rootkit blokuje v dalších neplechách. Během minuty mi Avast třeba 40x hlásí, že ho zablokoval. Až Avast vypnu, tak si Rootkit bude dělat, co bude chtít... Bojím, se že tomu PC víc ublížím.
Opravdu si mám deaktivovat Avast?
K.
Opravdu si mám deaktivovat Avast?
K.
- Rudy
- Site Admin
- Příspěvky: 119544
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Win64: Rootkit-gen
Ano, deaktivujte. Pokud tam rootkit opravdu je, Avast jeho aktivutám v podstatě nezabrání (kdyby mohl, smazal by ho), pouze ho detekuje. Bez deaktivace by nemusel CF provést korektní detekci.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Win64: Rootkit-gen
OK, vše jsem vypla, Avast deaktivovala. Program tam cosi prováděl. Teď už mám delší dobu na obrazovce jen log v poznámkovém bloku = můžu Avast zase zapnout a poslat vám to?
- Rudy
- Site Admin
- Příspěvky: 119544
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Win64: Rootkit-gen
Ano. Text zkopírujte běžnám způsobem (kopírovat>vložit).
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Win64: Rootkit-gen
ComboFix 14-08-31.01 - Slimaca 02.09.2014 19:32:30.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3327.2224 [GMT 2:00]
Spuštěný z: c:\users\Slimaca\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Slimaca\AppData\Local\Temp\mdi064.dll
c:\users\Slimaca\AppData\Roaming\ACD Systems\ACDSee\ImageDB.ddf
c:\users\Slimaca\AppData\Roaming\Microsoft\Windows\Recent\Link To Download MORE FREE Softwares and Apps.url
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-02 do 2014-09-02 )))))))))))))))))))))))))))))))
.
.
2014-09-02 17:41 . 2014-09-02 17:41 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-02 17:41 . 2014-09-02 17:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-02 16:46 . 2014-09-02 16:46 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\offreg.dll
2014-09-02 05:13 . 2014-09-02 08:42 -------- d-----w- c:\program files\trend micro
2014-09-02 05:13 . 2014-09-02 05:14 -------- d-----w- C:\rsit
2014-09-01 19:59 . 2014-09-01 19:59 -------- d-----w- c:\programdata\Malwarebytes
2014-09-01 19:59 . 2014-09-02 16:16 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-09-01 19:59 . 2014-09-02 15:57 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 19:58 . 2014-09-02 15:57 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 15:36 . 2014-09-01 15:37 -------- d-----w- c:\program files\CCleaner
2014-09-01 15:35 . 2014-09-01 15:35 -------- d-----w- c:\program files\Sophos
2014-08-31 15:04 . 2014-08-31 15:04 -------- d-----w- c:\program files\SGP Systems
2014-08-29 07:35 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\mpengine.dll
2014-08-28 10:43 . 2014-08-23 00:42 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-08-28 10:43 . 2014-08-23 01:46 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 11:36 . 2014-08-23 11:36 -------- d-----w- c:\program files\Common Files\Skype
2014-08-15 19:04 . 2014-08-15 19:04 -------- d-----w- c:\users\Slimaca\AppData\Local\Adobe
2014-08-14 01:06 . 2014-03-09 21:47 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 01:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 01:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 01:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 18:03 . 2014-07-16 02:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-13 18:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\system32\msi.dll
2014-08-13 18:03 . 2014-06-03 09:30 101824 ----a-w- c:\windows\system32\consent.exe
2014-08-13 18:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-08-13 18:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\system32\authui.dll
2014-08-13 18:02 . 2014-08-07 01:43 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 18:02 . 2014-08-07 01:39 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\users\Slimaca\AppData\Roaming\Oracle
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\program files\Common Files\Java
2014-08-06 18:07 . 2014-08-06 18:07 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-29 06:36 . 2012-07-17 12:37 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-14 07:52 . 2012-05-18 06:30 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-14 07:52 . 2012-05-18 06:30 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-08-05 07:20 . 2012-05-16 13:19 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-13 18:01 . 2012-05-16 13:06 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:00 . 2014-05-16 06:38 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-13 18:00 . 2014-01-21 18:52 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:00 . 2013-03-20 13:29 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:00 . 2013-03-20 13:29 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:00 . 2012-05-16 13:06 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:00 . 2012-05-16 13:06 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:00 . 2012-05-16 13:06 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:00 . 2014-07-13 18:00 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 18:00 . 2012-05-16 13:06 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 02:40 . 2014-07-09 02:40 5659136 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-06-18 01:51 . 2014-07-09 18:53 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-15 19:18 . 2014-06-15 19:19 737280 ----a-w- c:\windows\iun6002.exe
2014-06-06 09:44 . 2014-07-09 18:52 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26 . 2014-07-09 18:52 1059840 ----a-w- c:\windows\system32\lsasrv.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:00 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-01-22 92152]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-07-24 21650016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-03-27 10967656]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" [2010-05-13 110192]
"DT PLP"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2010-05-17 121456]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2565520]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"="c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-29 4085896]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-07-25 256896]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-5-28 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-07-25 108032]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\3AFC.tmp [x]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-17 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 07:52]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: Interfaces\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
FF - ProfilePath - c:\users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search
FF - ExtSQL: !HIDDEN! 2012-05-18 08:46; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST380811 rev.3.AA -> Harddisk0\DR0 -> \Device\00000061
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
malicious code @ sector 0x132c4977 size 0x1fd !
copy of MBR has been found in sector 62 !
sectors 156301486 (+255): user != kernel
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\3AFC.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-09-02 19:43:44
ComboFix-quarantined-files.txt 2014-09-02 17:43
.
Před spuštěním: Volných bajtů: 26 869 682 176
Po spuštění: Volných bajtů: 26 679 910 400
.
- - End Of File - - 447F1BDB27FB2CAF4D8E5B431FD7EFB0
8F558EB6672622401DA993E1E865C861
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3327.2224 [GMT 2:00]
Spuštěný z: c:\users\Slimaca\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Slimaca\AppData\Local\Temp\mdi064.dll
c:\users\Slimaca\AppData\Roaming\ACD Systems\ACDSee\ImageDB.ddf
c:\users\Slimaca\AppData\Roaming\Microsoft\Windows\Recent\Link To Download MORE FREE Softwares and Apps.url
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-02 do 2014-09-02 )))))))))))))))))))))))))))))))
.
.
2014-09-02 17:41 . 2014-09-02 17:41 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-02 17:41 . 2014-09-02 17:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-02 16:46 . 2014-09-02 16:46 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\offreg.dll
2014-09-02 05:13 . 2014-09-02 08:42 -------- d-----w- c:\program files\trend micro
2014-09-02 05:13 . 2014-09-02 05:14 -------- d-----w- C:\rsit
2014-09-01 19:59 . 2014-09-01 19:59 -------- d-----w- c:\programdata\Malwarebytes
2014-09-01 19:59 . 2014-09-02 16:16 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-09-01 19:59 . 2014-09-02 15:57 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 19:58 . 2014-09-02 15:57 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 15:36 . 2014-09-01 15:37 -------- d-----w- c:\program files\CCleaner
2014-09-01 15:35 . 2014-09-01 15:35 -------- d-----w- c:\program files\Sophos
2014-08-31 15:04 . 2014-08-31 15:04 -------- d-----w- c:\program files\SGP Systems
2014-08-29 07:35 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\mpengine.dll
2014-08-28 10:43 . 2014-08-23 00:42 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-08-28 10:43 . 2014-08-23 01:46 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 11:36 . 2014-08-23 11:36 -------- d-----w- c:\program files\Common Files\Skype
2014-08-15 19:04 . 2014-08-15 19:04 -------- d-----w- c:\users\Slimaca\AppData\Local\Adobe
2014-08-14 01:06 . 2014-03-09 21:47 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 01:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 01:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 01:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 18:03 . 2014-07-16 02:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-13 18:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\system32\msi.dll
2014-08-13 18:03 . 2014-06-03 09:30 101824 ----a-w- c:\windows\system32\consent.exe
2014-08-13 18:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-08-13 18:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\system32\authui.dll
2014-08-13 18:02 . 2014-08-07 01:43 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 18:02 . 2014-08-07 01:39 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\users\Slimaca\AppData\Roaming\Oracle
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\program files\Common Files\Java
2014-08-06 18:07 . 2014-08-06 18:07 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-29 06:36 . 2012-07-17 12:37 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-14 07:52 . 2012-05-18 06:30 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-14 07:52 . 2012-05-18 06:30 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-08-05 07:20 . 2012-05-16 13:19 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-13 18:01 . 2012-05-16 13:06 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:00 . 2014-05-16 06:38 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-13 18:00 . 2014-01-21 18:52 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:00 . 2013-03-20 13:29 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:00 . 2013-03-20 13:29 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:00 . 2012-05-16 13:06 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:00 . 2012-05-16 13:06 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:00 . 2012-05-16 13:06 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:00 . 2014-07-13 18:00 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 18:00 . 2012-05-16 13:06 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 02:40 . 2014-07-09 02:40 5659136 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-06-18 01:51 . 2014-07-09 18:53 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-15 19:18 . 2014-06-15 19:19 737280 ----a-w- c:\windows\iun6002.exe
2014-06-06 09:44 . 2014-07-09 18:52 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26 . 2014-07-09 18:52 1059840 ----a-w- c:\windows\system32\lsasrv.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:00 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-01-22 92152]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-07-24 21650016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-03-27 10967656]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" [2010-05-13 110192]
"DT PLP"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2010-05-17 121456]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2565520]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"="c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-29 4085896]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-07-25 256896]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-5-28 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-07-25 108032]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\3AFC.tmp [x]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-17 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 07:52]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: Interfaces\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
FF - ProfilePath - c:\users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search
FF - ExtSQL: !HIDDEN! 2012-05-18 08:46; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST380811 rev.3.AA -> Harddisk0\DR0 -> \Device\00000061
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
malicious code @ sector 0x132c4977 size 0x1fd !
copy of MBR has been found in sector 62 !
sectors 156301486 (+255): user != kernel
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\3AFC.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-09-02 19:43:44
ComboFix-quarantined-files.txt 2014-09-02 17:43
.
Před spuštěním: Volných bajtů: 26 869 682 176
Po spuštění: Volných bajtů: 26 679 910 400
.
- - End Of File - - 447F1BDB27FB2CAF4D8E5B431FD7EFB0
8F558EB6672622401DA993E1E865C861
- Rudy
- Site Admin
- Příspěvky: 119544
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Win64: Rootkit-gen
Jen na okraj: Avast deaktivován nebyl:

Jako další akci spusťte TDSSKiller: http://www.stahuj.centrum.cz/utility_a_ ... dsskiller/ . Uložte třeba na plochu, spusťte a nechte pracovat.Po ukončení akce sem dejte log.
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spsutí a vykoná příkazy ze skriptu.KillAll::
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

Jako další akci spusťte TDSSKiller: http://www.stahuj.centrum.cz/utility_a_ ... dsskiller/ . Uložte třeba na plochu, spusťte a nechte pracovat.Po ukončení akce sem dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Win64: Rootkit-gen

Ikona avastu nám zmizela z lišty vpravo dole (přes který není problém avast vypnout) - teď když Avast musíme lovit přes nabídku start, nejsme schopní najít tam nastavení vypnutí. Předtím jsem "nevypla Avast" přes Nastavení - Aktivní ochrana - a povypínala jsem štíty - nic jiného jsem nenašla...
- Rudy
- Site Admin
- Příspěvky: 119544
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Win64: Rootkit-gen
Mělo by to tak být. Snad bude vše v pořádku. Dejte po dočištění nový log CF.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Win64: Rootkit-gen
ComboFix 14-08-31.01 - Slimaca 02.09.2014 20:54:35.3.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3327.2206 [GMT 2:00]
Spuštěný z: c:\users\Slimaca\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-02 do 2014-09-02 )))))))))))))))))))))))))))))))
.
.
2014-09-02 19:01 . 2014-09-02 19:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-02 19:01 . 2014-09-02 19:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-02 16:46 . 2014-09-02 16:46 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\offreg.dll
2014-09-02 05:13 . 2014-09-02 08:42 -------- d-----w- c:\program files\trend micro
2014-09-02 05:13 . 2014-09-02 05:14 -------- d-----w- C:\rsit
2014-09-01 19:59 . 2014-09-01 19:59 -------- d-----w- c:\programdata\Malwarebytes
2014-09-01 19:59 . 2014-09-02 16:16 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-09-01 19:59 . 2014-09-02 15:57 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 19:58 . 2014-09-02 15:57 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 15:36 . 2014-09-01 15:37 -------- d-----w- c:\program files\CCleaner
2014-09-01 15:35 . 2014-09-01 15:35 -------- d-----w- c:\program files\Sophos
2014-08-31 15:04 . 2014-08-31 15:04 -------- d-----w- c:\program files\SGP Systems
2014-08-29 07:35 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\mpengine.dll
2014-08-28 10:43 . 2014-08-23 00:42 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-08-28 10:43 . 2014-08-23 01:46 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 11:36 . 2014-08-23 11:36 -------- d-----w- c:\program files\Common Files\Skype
2014-08-15 19:04 . 2014-08-15 19:04 -------- d-----w- c:\users\Slimaca\AppData\Local\Adobe
2014-08-14 01:06 . 2014-03-09 21:47 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 01:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 01:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 01:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 18:03 . 2014-07-16 02:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-13 18:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\system32\msi.dll
2014-08-13 18:03 . 2014-06-03 09:30 101824 ----a-w- c:\windows\system32\consent.exe
2014-08-13 18:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-08-13 18:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\system32\authui.dll
2014-08-13 18:02 . 2014-08-07 01:43 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 18:02 . 2014-08-07 01:39 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\users\Slimaca\AppData\Roaming\Oracle
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\program files\Common Files\Java
2014-08-06 18:07 . 2014-08-06 18:07 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-29 06:36 . 2012-07-17 12:37 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-14 07:52 . 2012-05-18 06:30 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-14 07:52 . 2012-05-18 06:30 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-08-05 07:20 . 2012-05-16 13:19 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-13 18:01 . 2012-05-16 13:06 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:00 . 2014-05-16 06:38 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-13 18:00 . 2014-01-21 18:52 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:00 . 2013-03-20 13:29 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:00 . 2013-03-20 13:29 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:00 . 2012-05-16 13:06 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:00 . 2012-05-16 13:06 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:00 . 2012-05-16 13:06 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:00 . 2014-07-13 18:00 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 18:00 . 2012-05-16 13:06 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 02:40 . 2014-07-09 02:40 5659136 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-06-18 01:51 . 2014-07-09 18:53 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-15 19:18 . 2014-06-15 19:19 737280 ----a-w- c:\windows\iun6002.exe
2014-06-06 09:44 . 2014-07-09 18:52 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26 . 2014-07-09 18:52 1059840 ----a-w- c:\windows\system32\lsasrv.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:00 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-01-22 92152]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-07-24 21650016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-03-27 10967656]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" [2010-05-13 110192]
"DT PLP"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2010-05-17 121456]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2565520]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"="c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-29 4085896]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-5-28 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-07-25 108032]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\3AFC.tmp [x]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-17 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 21276180
*NewlyCreated* - WS2IFSL
*Deregistered* - 21276180
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 07:52]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: Interfaces\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
FF - ProfilePath - c:\users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search
FF - ExtSQL: !HIDDEN! 2012-05-18 08:46; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST380811 rev.3.AA -> Harddisk0\DR0 -> \Device\00000062
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
malicious code @ sector 0x132c4977 size 0x1fd !
copy of MBR has been found in sector 62 !
sectors 156301486 (+255): user != kernel
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\3AFC.tmp"
.
Celkový čas: 2014-09-02 21:03:21
ComboFix-quarantined-files.txt 2014-09-02 19:03
ComboFix2.txt 2014-09-02 18:45
ComboFix3.txt 2014-09-02 17:43
.
Před spuštěním: Volných bajtů: 26 837 106 688
Po spuštění: Volných bajtů: 26 784 817 152
.
- - End Of File - - 59542913D9DE12D71135971D3B1DC621
8F558EB6672622401DA993E1E865C861
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3327.2206 [GMT 2:00]
Spuštěný z: c:\users\Slimaca\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-02 do 2014-09-02 )))))))))))))))))))))))))))))))
.
.
2014-09-02 19:01 . 2014-09-02 19:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-02 19:01 . 2014-09-02 19:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-02 16:46 . 2014-09-02 16:46 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\offreg.dll
2014-09-02 05:13 . 2014-09-02 08:42 -------- d-----w- c:\program files\trend micro
2014-09-02 05:13 . 2014-09-02 05:14 -------- d-----w- C:\rsit
2014-09-01 19:59 . 2014-09-01 19:59 -------- d-----w- c:\programdata\Malwarebytes
2014-09-01 19:59 . 2014-09-02 16:16 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-09-01 19:59 . 2014-09-02 15:57 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 19:58 . 2014-09-02 15:57 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 15:36 . 2014-09-01 15:37 -------- d-----w- c:\program files\CCleaner
2014-09-01 15:35 . 2014-09-01 15:35 -------- d-----w- c:\program files\Sophos
2014-08-31 15:04 . 2014-08-31 15:04 -------- d-----w- c:\program files\SGP Systems
2014-08-29 07:35 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\mpengine.dll
2014-08-28 10:43 . 2014-08-23 00:42 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-08-28 10:43 . 2014-08-23 01:46 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 11:36 . 2014-08-23 11:36 -------- d-----w- c:\program files\Common Files\Skype
2014-08-15 19:04 . 2014-08-15 19:04 -------- d-----w- c:\users\Slimaca\AppData\Local\Adobe
2014-08-14 01:06 . 2014-03-09 21:47 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 01:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 01:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 01:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 18:03 . 2014-07-16 02:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-13 18:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\system32\msi.dll
2014-08-13 18:03 . 2014-06-03 09:30 101824 ----a-w- c:\windows\system32\consent.exe
2014-08-13 18:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-08-13 18:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\system32\authui.dll
2014-08-13 18:02 . 2014-08-07 01:43 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 18:02 . 2014-08-07 01:39 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\users\Slimaca\AppData\Roaming\Oracle
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\program files\Common Files\Java
2014-08-06 18:07 . 2014-08-06 18:07 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-29 06:36 . 2012-07-17 12:37 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-14 07:52 . 2012-05-18 06:30 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-14 07:52 . 2012-05-18 06:30 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-08-05 07:20 . 2012-05-16 13:19 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-13 18:01 . 2012-05-16 13:06 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:00 . 2014-05-16 06:38 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-13 18:00 . 2014-01-21 18:52 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:00 . 2013-03-20 13:29 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:00 . 2013-03-20 13:29 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:00 . 2012-05-16 13:06 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:00 . 2012-05-16 13:06 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:00 . 2012-05-16 13:06 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:00 . 2014-07-13 18:00 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 18:00 . 2012-05-16 13:06 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 02:40 . 2014-07-09 02:40 5659136 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-06-18 01:51 . 2014-07-09 18:53 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-15 19:18 . 2014-06-15 19:19 737280 ----a-w- c:\windows\iun6002.exe
2014-06-06 09:44 . 2014-07-09 18:52 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26 . 2014-07-09 18:52 1059840 ----a-w- c:\windows\system32\lsasrv.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:00 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-01-22 92152]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-07-24 21650016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-03-27 10967656]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" [2010-05-13 110192]
"DT PLP"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2010-05-17 121456]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2565520]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"="c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-29 4085896]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-5-28 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-07-25 108032]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\3AFC.tmp [x]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-17 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 21276180
*NewlyCreated* - WS2IFSL
*Deregistered* - 21276180
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 07:52]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: Interfaces\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
FF - ProfilePath - c:\users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search
FF - ExtSQL: !HIDDEN! 2012-05-18 08:46; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST380811 rev.3.AA -> Harddisk0\DR0 -> \Device\00000062
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
malicious code @ sector 0x132c4977 size 0x1fd !
copy of MBR has been found in sector 62 !
sectors 156301486 (+255): user != kernel
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\3AFC.tmp"
.
Celkový čas: 2014-09-02 21:03:21
ComboFix-quarantined-files.txt 2014-09-02 19:03
ComboFix2.txt 2014-09-02 18:45
ComboFix3.txt 2014-09-02 17:43
.
Před spuštěním: Volných bajtů: 26 837 106 688
Po spuštění: Volných bajtů: 26 784 817 152
.
- - End Of File - - 59542913D9DE12D71135971D3B1DC621
8F558EB6672622401DA993E1E865C861
- Rudy
- Site Admin
- Příspěvky: 119544
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Win64: Rootkit-gen
Smazáno. Nyní spusťte ten TDSSKiller a pak dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Win64: Rootkit-gen
ComboFix 14-08-31.01 - Slimaca 02.09.2014 21:36:01.4.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3327.2143 [GMT 2:00]
Spuštěný z: f:\kaŕka\Antivir\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-02 do 2014-09-02 )))))))))))))))))))))))))))))))
.
.
2014-09-02 19:42 . 2014-09-02 19:42 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-02 19:42 . 2014-09-02 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-02 16:46 . 2014-09-02 16:46 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\offreg.dll
2014-09-02 05:13 . 2014-09-02 08:42 -------- d-----w- c:\program files\trend micro
2014-09-02 05:13 . 2014-09-02 05:14 -------- d-----w- C:\rsit
2014-09-01 19:59 . 2014-09-01 19:59 -------- d-----w- c:\programdata\Malwarebytes
2014-09-01 19:59 . 2014-09-02 16:16 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-09-01 19:59 . 2014-09-02 15:57 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 19:58 . 2014-09-02 15:57 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 15:36 . 2014-09-01 15:37 -------- d-----w- c:\program files\CCleaner
2014-09-01 15:35 . 2014-09-01 15:35 -------- d-----w- c:\program files\Sophos
2014-08-31 15:04 . 2014-08-31 15:04 -------- d-----w- c:\program files\SGP Systems
2014-08-29 07:35 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\mpengine.dll
2014-08-28 10:43 . 2014-08-23 00:42 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-08-28 10:43 . 2014-08-23 01:46 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 11:36 . 2014-08-23 11:36 -------- d-----w- c:\program files\Common Files\Skype
2014-08-15 19:04 . 2014-08-15 19:04 -------- d-----w- c:\users\Slimaca\AppData\Local\Adobe
2014-08-14 01:06 . 2014-03-09 21:47 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 01:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 01:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 01:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 18:03 . 2014-07-16 02:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-13 18:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\system32\msi.dll
2014-08-13 18:03 . 2014-06-03 09:30 101824 ----a-w- c:\windows\system32\consent.exe
2014-08-13 18:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-08-13 18:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\system32\authui.dll
2014-08-13 18:02 . 2014-08-07 01:43 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 18:02 . 2014-08-07 01:39 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\users\Slimaca\AppData\Roaming\Oracle
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\program files\Common Files\Java
2014-08-06 18:07 . 2014-08-06 18:07 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-29 06:36 . 2012-07-17 12:37 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-14 07:52 . 2012-05-18 06:30 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-14 07:52 . 2012-05-18 06:30 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-08-05 07:20 . 2012-05-16 13:19 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-13 18:01 . 2012-05-16 13:06 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:00 . 2014-05-16 06:38 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-13 18:00 . 2014-01-21 18:52 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:00 . 2013-03-20 13:29 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:00 . 2013-03-20 13:29 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:00 . 2012-05-16 13:06 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:00 . 2012-05-16 13:06 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:00 . 2012-05-16 13:06 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:00 . 2014-07-13 18:00 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 18:00 . 2012-05-16 13:06 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 02:40 . 2014-07-09 02:40 5659136 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-06-18 01:51 . 2014-07-09 18:53 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-15 19:18 . 2014-06-15 19:19 737280 ----a-w- c:\windows\iun6002.exe
2014-06-06 09:44 . 2014-07-09 18:52 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26 . 2014-07-09 18:52 1059840 ----a-w- c:\windows\system32\lsasrv.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:00 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-01-22 92152]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-07-24 21650016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-03-27 10967656]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" [2010-05-13 110192]
"DT PLP"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2010-05-17 121456]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2565520]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"="c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-29 4085896]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-5-28 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-07-25 108032]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\3AFC.tmp [x]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-17 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 21276180
*NewlyCreated* - WS2IFSL
*Deregistered* - 21276180
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 07:52]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: Interfaces\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
FF - ProfilePath - c:\users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search
FF - ExtSQL: !HIDDEN! 2012-05-18 08:46; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST380811 rev.3.AA -> Harddisk0\DR0 -> \Device\00000062
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
malicious code @ sector 0x132c4977 size 0x1fd !
copy of MBR has been found in sector 62 !
sectors 156301486 (+255): user != kernel
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\3AFC.tmp"
.
Celkový čas: 2014-09-02 21:44:00
ComboFix-quarantined-files.txt 2014-09-02 19:43
ComboFix2.txt 2014-09-02 19:03
ComboFix3.txt 2014-09-02 18:45
ComboFix4.txt 2014-09-02 17:43
.
Před spuštěním: Volných bajtů: 26 858 901 504
Po spuštění: Volných bajtů: 26 806 947 840
.
- - End Of File - - 12D494B4274AF3EAB1FCCE1854F630F4
8F558EB6672622401DA993E1E865C861
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3327.2143 [GMT 2:00]
Spuštěný z: f:\kaŕka\Antivir\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-02 do 2014-09-02 )))))))))))))))))))))))))))))))
.
.
2014-09-02 19:42 . 2014-09-02 19:42 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-09-02 19:42 . 2014-09-02 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-02 16:46 . 2014-09-02 16:46 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\offreg.dll
2014-09-02 05:13 . 2014-09-02 08:42 -------- d-----w- c:\program files\trend micro
2014-09-02 05:13 . 2014-09-02 05:14 -------- d-----w- C:\rsit
2014-09-01 19:59 . 2014-09-01 19:59 -------- d-----w- c:\programdata\Malwarebytes
2014-09-01 19:59 . 2014-09-02 16:16 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-09-01 19:59 . 2014-09-02 15:57 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-01 19:58 . 2014-09-02 15:57 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-01 15:36 . 2014-09-01 15:37 -------- d-----w- c:\program files\CCleaner
2014-09-01 15:35 . 2014-09-01 15:35 -------- d-----w- c:\program files\Sophos
2014-08-31 15:04 . 2014-08-31 15:04 -------- d-----w- c:\program files\SGP Systems
2014-08-29 07:35 . 2014-08-21 02:44 8581864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2830AD8-02D5-43F7-826D-1357C791AC7C}\mpengine.dll
2014-08-28 10:43 . 2014-08-23 00:42 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-08-28 10:43 . 2014-08-23 01:46 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 11:36 . 2014-08-23 11:36 -------- d-----w- c:\program files\Common Files\Skype
2014-08-15 19:04 . 2014-08-15 19:04 -------- d-----w- c:\users\Slimaca\AppData\Local\Adobe
2014-08-14 01:06 . 2014-03-09 21:47 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-14 01:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-14 01:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\system32\icardagt.exe
2014-08-14 01:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 18:03 . 2014-07-16 02:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-13 18:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\system32\msi.dll
2014-08-13 18:03 . 2014-06-03 09:30 101824 ----a-w- c:\windows\system32\consent.exe
2014-08-13 18:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-08-13 18:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\system32\authui.dll
2014-08-13 18:02 . 2014-08-07 01:43 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 18:02 . 2014-08-07 01:39 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-08-13 18:01 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\users\Slimaca\AppData\Roaming\Oracle
2014-08-06 18:08 . 2014-08-06 18:08 -------- d-----w- c:\program files\Common Files\Java
2014-08-06 18:07 . 2014-08-06 18:07 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-29 06:36 . 2012-07-17 12:37 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-14 07:52 . 2012-05-18 06:30 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-14 07:52 . 2012-05-18 06:30 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-08-05 07:20 . 2012-05-16 13:19 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-07-13 18:01 . 2012-05-16 13:06 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-13 18:00 . 2014-05-16 06:38 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-13 18:00 . 2014-01-21 18:52 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-13 18:00 . 2013-03-20 13:29 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-13 18:00 . 2013-03-20 13:29 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-13 18:00 . 2012-05-16 13:06 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-13 18:00 . 2012-05-16 13:06 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-13 18:00 . 2012-05-16 13:06 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-13 18:00 . 2014-07-13 18:00 43152 ----a-w- c:\windows\avastSS.scr
2014-07-13 18:00 . 2012-05-16 13:06 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-09 02:40 . 2014-07-09 02:40 5659136 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-06-18 01:51 . 2014-07-09 18:53 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-15 19:18 . 2014-06-15 19:19 737280 ----a-w- c:\windows\iun6002.exe
2014-06-06 09:44 . 2014-07-09 18:52 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26 . 2014-07-09 18:52 1059840 ----a-w- c:\windows\system32\lsasrv.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-13 18:00 578240 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Slimaca\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-01-22 92152]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-07-24 21650016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-03-27 10967656]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" [2010-05-13 110192]
"DT PLP"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2010-05-17 121456]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2565520]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]
"IJNetworkScannerSelectorEX"="c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-29 4085896]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-5-28 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys [2010-05-26 74752]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-07-25 108032]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\3AFC.tmp [x]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys [2010-05-26 6144]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-17 1343400]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-13 414520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-17 242240]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 21276180
*NewlyCreated* - WS2IFSL
*Deregistered* - 21276180
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 07:52]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Slimaca\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: Interfaces\{6DFAFB2D-4156-4D35-A0B6-5D17B8483AD0}: NameServer = 213.46.172.36,213.46.172.37
FF - ProfilePath - c:\users\Slimaca\AppData\Roaming\Mozilla\Firefox\Profiles\kwp5b3n3.default\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search
FF - ExtSQL: !HIDDEN! 2012-05-18 08:46; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: ST380811 rev.3.AA -> Harddisk0\DR0 -> \Device\00000062
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
malicious code @ sector 0x132c4977 size 0x1fd !
copy of MBR has been found in sector 62 !
sectors 156301486 (+255): user != kernel
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\3AFC.tmp"
.
Celkový čas: 2014-09-02 21:44:00
ComboFix-quarantined-files.txt 2014-09-02 19:43
ComboFix2.txt 2014-09-02 19:03
ComboFix3.txt 2014-09-02 18:45
ComboFix4.txt 2014-09-02 17:43
.
Před spuštěním: Volných bajtů: 26 858 901 504
Po spuštění: Volných bajtů: 26 806 947 840
.
- - End Of File - - 12D494B4274AF3EAB1FCCE1854F630F4
8F558EB6672622401DA993E1E865C861