ComboFix 17-10-17.01 - Zdeněk 10/28/2017 13:50:17.2.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8080.6314 [GMT 2:00]
Spuštěný z: c:\users\Zdenýk\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Zdenýk\Desktop\CFScript.txt
AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2017-09-28 do 2017-10-28 )))))))))))))))))))))))))))))))
.
.
2017-10-28 11:54 . 2017-10-28 11:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-10-28 10:24 . 2017-10-28 10:24 -------- d-----w- c:\users\Zdenek
2017-10-28 10:22 . 2017-10-28 10:22 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D482F44E-3AB6-4160-B186-39768C45FEB1}\offreg.1720.dll
2017-10-28 10:12 . 2017-10-28 10:12 203680 ----a-w- c:\windows\system32\drivers\zam64.sys
2017-10-28 10:12 . 2017-10-28 10:12 203680 ----a-w- c:\windows\system32\drivers\zamguard64.sys
2017-10-28 10:12 . 2017-10-28 10:12 -------- d-----w- c:\program files (x86)\Zemana AntiMalware
2017-10-28 10:05 . 2017-10-28 09:53 24064 ----a-w- c:\windows\zoek-delete.exe
2017-10-28 09:53 . 2017-10-28 10:03 -------- d-----w- C:\zoek_backup
2017-10-28 02:30 . 2017-10-28 02:30 13753048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D482F44E-3AB6-4160-B186-39768C45FEB1}\mpengine.dll
2017-10-27 20:23 . 2017-10-28 09:38 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-10-27 19:57 . 2017-10-27 19:57 -------- d-----w- c:\programdata\Sophos
2017-10-27 19:56 . 2017-10-27 19:56 -------- d-----w- c:\program files (x86)\Sophos
2017-10-27 18:22 . 2017-10-04 11:15 77440 ----a-w- c:\windows\system32\drivers\mbae64.sys
2017-10-27 18:22 . 2017-10-27 18:22 -------- d-----w- c:\programdata\Malwarebytes
2017-10-27 16:33 . 2017-10-27 16:33 -------- d-----w- c:\programdata\Ashampoo
2017-10-27 16:33 . 2017-10-27 16:33 -------- d-----w- c:\program files (x86)\Ashampoo
2017-10-27 13:11 . 2017-10-27 13:11 -------- d-----w- c:\program files (x86)\Nero
2017-10-27 13:10 . 2017-10-27 13:11 -------- d-----w- c:\program files (x86)\Common Files\Nero
2017-10-27 13:10 . 2017-10-27 13:11 -------- d-----w- c:\programdata\Nero
2017-10-26 23:53 . 2016-01-27 02:03 122320 ----a-w- c:\windows\system32\CONEQMSAPOGUILibrary.dll
2017-10-26 23:53 . 2016-01-27 02:03 574760 ----a-w- c:\windows\system32\AERTAC64.dll
2017-10-26 23:53 . 2016-01-27 02:03 118600 ----a-w- c:\windows\system32\AERTAR64.dll
2017-10-26 23:49 . 2016-08-16 21:54 11776 ----a-w- c:\windows\system32\drivers\cs-CZ\usbhub.sys.mui
2017-10-26 23:44 . 2017-10-26 23:44 -------- d-----w- c:\program files (x86)\MSXML 4.0
2017-10-26 23:43 . 2017-10-26 23:43 -------- d-----w- c:\programdata\DriverTalent
2017-10-26 23:42 . 2017-10-26 23:43 -------- d-----w- C:\OSTotoFolder
2017-10-26 23:42 . 2017-10-26 23:46 -------- d-----w- c:\program files (x86)\OSTotoSoft
2017-10-26 22:20 . 2017-10-26 22:44 -------- d-----w- c:\program files (x86)\Intel Driver and Support Assistant
2017-10-26 22:20 . 2016-10-18 15:14 21984 ----a-w- c:\windows\system32\drivers\semav6msr64.sys
2017-10-26 22:20 . 2017-10-26 22:20 -------- d-----w- c:\program files\Intel Driver and Support Assistant
2017-10-26 21:56 . 2017-10-26 21:56 -------- d-----w- c:\programdata\SWCUTemp
2017-10-26 20:01 . 2017-10-26 20:01 -------- d-----w- c:\program files\CPUID
2017-10-26 19:06 . 2017-10-27 18:16 -------- d-----w- C:\AdwCleaner
2017-10-26 19:03 . 2017-10-27 20:22 -------- d-----w- c:\programdata\RogueKiller
2017-10-26 19:02 . 2017-10-27 18:22 -------- d-----w- c:\program files\Malwarebytes
2017-10-22 13:19 . 2017-10-26 21:37 -------- d-----w- c:\program files (x86)\GIGABYTE
2017-10-22 13:12 . 2016-07-22 14:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2017-10-22 13:12 . 2016-07-22 14:51 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2017-10-22 12:52 . 2017-10-26 21:37 -------- d-----w- c:\program files (x86)\RivaTuner Statistics Server
2017-10-22 12:51 . 2017-10-26 21:37 -------- d-----w- c:\program files (x86)\MSI Afterburner
2017-10-22 12:48 . 2017-10-26 21:38 -------- d-----w- c:\program files\MSI Kombustor 3
2017-10-22 12:47 . 2015-07-16 19:12 6131200 ----a-w- c:\windows\SysWow64\mstscax.dll
2017-10-22 12:47 . 2015-07-16 19:11 7077376 ----a-w- c:\windows\system32\mstscax.dll
2017-10-22 12:47 . 2015-07-16 19:11 1057792 ----a-w- c:\windows\system32\rdvidcrl.dll
2017-10-22 12:47 . 2015-07-11 13:15 429568 ----a-w- c:\windows\system32\wksprt.exe
2017-10-22 12:47 . 2015-07-16 19:12 856064 ----a-w- c:\windows\SysWow64\rdvidcrl.dll
2017-10-22 12:47 . 2015-07-16 19:12 53248 ----a-w- c:\windows\SysWow64\tsgqec.dll
2017-10-22 12:47 . 2015-07-16 19:11 62976 ----a-w- c:\windows\system32\tsgqec.dll
2017-10-22 12:46 . 2014-12-11 17:47 87040 ----a-w- c:\windows\system32\TSWbPrxy.exe
2017-10-21 23:09 . 2017-10-21 23:09 -------- d-----w- c:\windows\system32\wbem\Framework
2017-10-21 22:57 . 2017-10-26 21:33 -------- d-----w- C:\NVIDIA
2017-10-21 20:09 . 2016-03-23 22:40 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2017-10-21 20:09 . 2016-03-23 22:40 3181568 ----a-w- c:\windows\system32\rdpcorets.dll
2017-10-21 20:09 . 2017-03-07 14:05 243200 ----a-w- c:\windows\system32\rdpudd.dll
2017-10-21 19:51 . 2013-10-02 01:10 44544 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll
2017-10-21 19:51 . 2013-10-02 04:38 3072 ----a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui
2017-10-21 19:51 . 2013-10-02 02:22 56832 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2017-10-21 19:51 . 2013-10-02 02:11 13824 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2017-10-21 19:51 . 2013-10-02 02:08 12800 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2017-10-21 19:51 . 2013-10-02 01:48 56832 ----a-w- c:\windows\system32\MsRdpWebAccess.dll
2017-10-21 19:51 . 2013-10-02 01:48 18944 ----a-w- c:\windows\system32\wksprtPS.dll
2017-10-21 19:51 . 2013-10-02 00:14 50176 ----a-w- c:\windows\SysWow64\MsRdpWebAccess.dll
2017-10-21 19:51 . 2013-10-02 00:14 17920 ----a-w- c:\windows\SysWow64\wksprtPS.dll
2017-10-21 19:51 . 2013-10-01 23:31 1147392 ----a-w- c:\windows\system32\mstsc.exe
2017-10-21 19:51 . 2013-10-01 22:34 1068544 ----a-w- c:\windows\SysWow64\mstsc.exe
2017-10-21 19:47 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2017-10-21 19:47 . 2012-08-23 14:08 30208 ----a-w- c:\windows\system32\drivers\TsUsbGD.sys
2017-10-21 19:47 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2017-10-21 19:47 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2017-10-21 19:42 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL
2017-10-21 19:42 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDTAT.DLL
2017-10-21 19:42 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDRU1.DLL
2017-10-21 19:42 . 2014-07-09 02:03 6656 ----a-w- c:\windows\system32\KBDRU.DLL
2017-10-21 19:42 . 2014-07-09 01:31 7168 ----a-w- c:\windows\SysWow64\KBDYAK.DLL
2017-10-21 19:42 . 2014-07-09 01:31 6656 ----a-w- c:\windows\SysWow64\KBDBASH.DLL
2017-10-21 19:42 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDBASH.DLL
2017-10-21 19:41 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll
2017-10-21 19:41 . 2015-01-09 03:14 950272 ----a-w- c:\windows\system32\perftrack.dll
2017-10-21 19:41 . 2015-01-09 03:14 29696 ----a-w- c:\windows\system32\powertracker.dll
2017-10-21 19:41 . 2015-01-09 02:48 76800 ----a-w- c:\windows\SysWow64\wdi.dll
2017-10-21 19:39 . 2017-09-07 17:08 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\usbehci.sys.mui
2017-10-21 17:08 . 2017-10-21 17:08 -------- d-----w- c:\program files (x86)\EasyAntiCheat
2017-10-21 15:26 . 2017-10-21 15:26 -------- d-s---w- c:\windows\system32\CompatTel
2017-10-21 15:26 . 2017-10-21 15:26 -------- d-----w- c:\windows\system32\appraiser
2017-10-21 10:10 . 2017-10-21 10:10 -------- d-----w- c:\programdata\Microsoft Toolkit
2017-10-21 09:33 . 2017-10-21 09:33 8946680 ----a-w- c:\windows\system32\drivers\FACEIT.sys
2017-10-21 09:33 . 2017-10-21 09:33 -------- d-----w- c:\program files\FACEIT
2017-10-21 09:33 . 2017-10-21 09:33 -------- d-----w- c:\program files\FACEIT AC
2017-10-21 09:25 . 2017-10-11 01:05 50624 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2017-10-20 23:06 . 2017-10-20 23:06 -------- d-----w- c:\windows\SysWow64\Wat
2017-10-20 23:06 . 2017-10-20 23:06 -------- d-----w- c:\windows\system32\Wat
2017-10-20 22:54 . 2015-07-30 13:13 103120 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2017-10-20 22:54 . 2015-07-30 13:13 124624 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-10-20 22:52 . 2017-10-20 22:54 -------- d-----w- c:\windows\system32\MRT
2017-10-20 22:52 . 2017-10-20 22:52 126925120 -c--a-w- c:\windows\system32\MRT-KB890830.exe
2017-10-20 22:50 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2017-10-20 22:15 . 2017-10-20 22:15 -------- d-----w- c:\windows\Migration
2017-10-20 22:11 . 2017-09-13 15:32 95464 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2017-10-20 22:02 . 2016-04-09 04:20 1230848 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2017-10-20 22:02 . 2016-04-09 03:52 1424896 ----a-w- c:\windows\system32\WindowsCodecs.dll
2017-10-20 22:02 . 2015-02-04 03:16 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2017-10-20 22:02 . 2015-02-04 02:54 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2017-10-19 16:10 . 2017-10-19 16:10 -------- d-----w- c:\program files\TeamSpeak 3 Client
2017-10-19 15:24 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2017-10-19 15:24 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2017-10-19 15:24 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2017-10-19 15:24 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2017-10-19 15:24 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2017-10-19 15:24 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2017-10-19 15:24 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2017-10-19 15:13 . 2017-04-27 22:50 3550208 ----a-w- c:\windows\SysWow64\D3DCompiler_47.dll
2017-10-19 15:13 . 2017-04-12 13:05 4296704 ----a-w- c:\windows\system32\D3DCompiler_47.dll
2017-10-19 15:06 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2017-10-19 15:06 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2017-10-19 15:06 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2017-10-19 15:06 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2017-10-19 15:06 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2017-10-19 15:06 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2017-10-19 15:06 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2017-10-19 15:06 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2017-10-19 15:02 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
2017-10-19 15:02 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2017-10-19 15:01 . 2015-07-23 00:02 879104 ----a-w- c:\windows\system32\tdh.dll
2017-10-19 15:01 . 2015-07-22 17:53 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2017-10-19 14:59 . 2015-07-15 18:10 1743360 ----a-w- c:\windows\system32\sysmain.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-09-13 23:20 . 2017-09-13 23:20 798008 ----a-w- c:\windows\SysWow64\vulkan-1-1-0-61-0.dll
2017-09-13 23:20 . 2017-09-13 23:20 490296 ----a-w- c:\windows\SysWow64\vulkaninfo-1-1-0-61-0.exe
2017-09-13 23:19 . 2017-09-13 23:19 927544 ----a-w- c:\windows\system32\vulkan-1-1-0-61-0.dll
2017-09-13 23:19 . 2017-09-13 23:19 591160 ----a-w- c:\windows\system32\vulkaninfo-1-1-0-61-0.exe
2017-09-13 15:08 . 2017-10-20 22:12 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2017-10-25 3102496]
"ASUS ROG Armoury"="" [BU]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2017-09-20 9856176]
"FACEIT"="c:\program files\FACEIT\FACEIT.exe" [2017-10-03 81046232]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2014-02-21 292848]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2017-09-05 587288]
"DSATray"="c:\program files (x86)\Intel Driver and Support Assistant\DsaTray.exe" [2017-09-18 131360]
.
c:\users\Zdeněk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
GIGABYTE XTREME GAMING ENGINE.lnk - c:\program files (x86)\GIGABYTE\XTREME GAMING ENGINE\autorun.exe /r [2017-10-22 172176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
R2 NvTelemetryContainer;NVIDIA Telemetry Container;c:\program files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe;c:\program files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\program files (x86)\EasyAntiCheat\EasyAntiCheat.exe;c:\program files (x86)\EasyAntiCheat\EasyAntiCheat.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
R3 NvStreamKms;NVIDIA KMS;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 PAExec;PAExec;c:\windows\PAExec.exe;c:\windows\PAExec.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USER_ESRV_SVC_QUEENCREEK;User Energy Server Service queencreek;c:\program files\Intel\SUR\QUEENCREEK\esrv_svc.exe;c:\program files\Intel\SUR\QUEENCREEK\esrv_svc.exe [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 FACEIT;FACEIT;c:\windows\System32\Drivers\FACEIT.sys;c:\windows\SYSNATIVE\Drivers\FACEIT.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 ZAM;ZAM Helper Driver;c:\windows\System32\drivers\zam64.sys;c:\windows\SYSNATIVE\drivers\zam64.sys [x]
S1 ZAM_Guard;ZAM Guard Driver;c:\windows\System32\drivers\zamguard64.sys;c:\windows\SYSNATIVE\drivers\zamguard64.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 DSAService;Intel(R) Driver & Support Assistant;c:\program files (x86)\Intel Driver and Support Assistant\DSAService.exe;c:\program files (x86)\Intel Driver and Support Assistant\DSAService.exe [x]
S2 ESRV_SVC_QUEENCREEK;Energy Server Service queencreek;c:\program files\Intel\SUR\QUEENCREEK\esrv_svc.exe;c:\program files\Intel\SUR\QUEENCREEK\esrv_svc.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;c:\windows\system32\igfxCUIService.exe;c:\windows\SYSNATIVE\igfxCUIService.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 LHelperSvc;Local Helper Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
S2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [x]
S2 SystemUsageReportSvc_QUEENCREEK;Intel(R) System Usage Report Service SystemUsageReportSvc_QUEENCREEK;c:\program files\Intel Driver and Support Assistant\SUR\SurSvc.exe;c:\program files\Intel Driver and Support Assistant\SUR\SurSvc.exe [x]
S2 ZAMSvc;ZAM Controller Service;c:\program files (x86)\Zemana AntiMalware\ZAM.exe;c:\program files (x86)\Zemana AntiMalware\ZAM.exe [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 nvvhci;NVVHCI Enumerator Service;c:\windows\system32\DRIVERS\nvvhci.sys;c:\windows\SYSNATIVE\DRIVERS\nvvhci.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 semav6msr64;semav6msr64;c:\windows\system32\drivers\semav6msr64.sys;c:\windows\SYSNATIVE\drivers\semav6msr64.sys [x]
S3 XtuAcpiDriver;Intel(R) Extreme Tuning Utility Device Service;c:\windows\system32\DRIVERS\XtuAcpiDriver.sys;c:\windows\SYSNATIVE\DRIVERS\XtuAcpiDriver.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ESPROTECTIONDRIVER
*NewlyCreated* - MBAMFARFLT
*NewlyCreated* - MBAMPROTECTION
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - MBAMWEBPROTECTION
*NewlyCreated* - ZAM
*NewlyCreated* - ZAM_GUARD
*Deregistered* - ESProtectionDriver
*Deregistered* - MBAMFarflt
*Deregistered* - MBAMProtection
*Deregistered* - MBAMSwissArmy
*Deregistered* - MBAMWebProtection
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
LocalDriverService REG_MULTI_SZ LDrvSvc
LocalHelperService REG_MULTI_SZ LHelperSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2017-10-19 10:37 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.66\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveBlacklisted]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2017-10-09 08:33 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSynced]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2017-10-09 08:33 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSyncing]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2017-10-09 08:33 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2014-04-11 36352]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2016-01-27 16418560]
"ZAM"="c:\program files (x86)\Zemana AntiMalware\ZAM.exe" [2017-08-09 15775888]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
hxxp://www.google.com/mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} - (no file)
AddRemove-{01f3f6b8-1a81-4b10-b51f-f69af12e1d69} - c:\programdata\Package Cache\{01f3f6b8-1a81-4b10-b51f-f69af12e1d69}\Intel Driver and Support Assistant Installer.exe
AddRemove-{7f51bdb9-ee21-49ee-94d6-90afc321780e} - c:\programdata\Package Cache\{7f51bdb9-ee21-49ee-94d6-90afc321780e}\vcredist_x64.exe
AddRemove-{ce085a78-074e-4823-8dc1-8a721b94b76d} - c:\programdata\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
AddRemove-{d992c12e-cab2-426f-bde3-fb8c53950b0d} - c:\programdata\Package Cache\{d992c12e-cab2-426f-bde3-fb8c53950b0d}\VC_redist.x64.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2017-10-28 13:55:17
ComboFix-quarantined-files.txt 2017-10-28 11:55
ComboFix2.txt 2017-10-28 10:27
ComboFix3.txt 2017-10-26 19:35
.
Před spuštěním: Volných bajtů: 921,703,690,240
Po spuštění: Volných bajtů: 921,626,382,336
.
- - End Of File - - 9C82DBA3832135F17E743CBEC8B6B61F
5FB38429D5D77768867C76DCBDB35194