MS Removal Tool - Kontrola HJT
Napsal: 25 dub 2011 20:24
Dobrý den,
mám stejný poblám s MS Removal Tool, mohl bych poprosit taktéž o pomoc? Zde je log z programu ComboFix:
ComboFix 11-04-25.01 - oem 25.04.2011 18:57:31.1.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3959.3205 [GMT 1:00]
Spuštěný z: c:\users\oem\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Naver
c:\program files (x86)\Naver\NaverToolbar\DB_1_7.DAT
c:\program files (x86)\Naver\NaverToolbar\fixIE.exe
c:\program files (x86)\Naver\NaverToolbar\hangametetris\7souls.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\blog.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\bookmark.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\bookmark.JPG
c:\program files (x86)\Naver\NaverToolbar\hangametetris\bout.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\c9.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\capturebrowser.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\capturebrowser.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\cleaninternet.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\cleaninternet.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\clinic.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\config.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dic.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dicdetail.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dicdetail2.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dictionary.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\double.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\flashgame.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gamepack.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gametalk.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gametalk.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gmahjong.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\golf.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gunster.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gzs.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\hangamebi.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\hon.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\lasvagas.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\login.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\logo.bmp
c:\program files (x86)\Naver\NaverToolbar\hangametetris\logo.png
c:\program files (x86)\Naver\NaverToolbar\hangametetris\logout.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\magu.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\mhf.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\move.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\msduelgo.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\myblog.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\new.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\newgostop.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\opencast.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\opencast.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\pcclinic.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\Popojoy.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\popup.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\popup2.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\r2.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\real.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\search.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\seven.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\shortadr.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\shotcut.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\solitaire.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\TalesRunner.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\tera.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\tetris.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\theme.xml
c:\program files (x86)\Naver\NaverToolbar\hangametetris\toolbarcleaner.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\toolbarcleaner.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\transjapan.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\virus.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\yut.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\z9.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\zoom.ico
c:\program files (x86)\Naver\NaverToolbar\InstlInfo.ini
c:\program files (x86)\Naver\NaverToolbar\juniver\artist.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\babystudy.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\blog.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\bookmark.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\bookmark.JPG
c:\program files (x86)\Naver\NaverToolbar\juniver\capturebrowser.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\capturebrowser.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\cleaninternet.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\cleaninternet.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\clinic.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\comic.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\config.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\dic.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\dicdetail.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\dicdetail2.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\dictionary.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\dongwha.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\farm_01.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\farm_02.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\flash.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gabe.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gallery.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\game.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gametalk.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gametalk.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\homework.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\jr.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\kidsong.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\login.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\logo.bmp
c:\program files (x86)\Naver\NaverToolbar\juniver\logo.png
c:\program files (x86)\Naver\NaverToolbar\juniver\logout.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\move.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\opencast.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\opencast.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\panyroom.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\parents.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\pcclinic.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\popup.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\popup2.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\real.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\search.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\shotcut.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\theme.xml
c:\program files (x86)\Naver\NaverToolbar\juniver\toolbarcleaner.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\toolbarcleaner.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\transjapan.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\tv.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\virus.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\zoom.ico
c:\program files (x86)\Naver\NaverToolbar\naver\blog.ico
c:\program files (x86)\Naver\NaverToolbar\naver\bookmark.ico
c:\program files (x86)\Naver\NaverToolbar\naver\bookmark.JPG
c:\program files (x86)\Naver\NaverToolbar\naver\capturebrowser.ico
c:\program files (x86)\Naver\NaverToolbar\naver\capturebrowser.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\cleaninternet.ico
c:\program files (x86)\Naver\NaverToolbar\naver\cleaninternet.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\clinic.ico
c:\program files (x86)\Naver\NaverToolbar\naver\config.ico
c:\program files (x86)\Naver\NaverToolbar\naver\dic.ico
c:\program files (x86)\Naver\NaverToolbar\naver\dicdetail.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\dicdetail2.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\dictionary.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\gametalk.ico
c:\program files (x86)\Naver\NaverToolbar\naver\gametalk.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\login.ico
c:\program files (x86)\Naver\NaverToolbar\naver\logo.bmp
c:\program files (x86)\Naver\NaverToolbar\naver\logo.png
c:\program files (x86)\Naver\NaverToolbar\naver\logout.ico
c:\program files (x86)\Naver\NaverToolbar\naver\move.ico
c:\program files (x86)\Naver\NaverToolbar\naver\naver.ico
c:\program files (x86)\Naver\NaverToolbar\naver\opencast.ico
c:\program files (x86)\Naver\NaverToolbar\naver\opencast.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\pcclinic.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\popup.ico
c:\program files (x86)\Naver\NaverToolbar\naver\popup2.ico
c:\program files (x86)\Naver\NaverToolbar\naver\real.ico
c:\program files (x86)\Naver\NaverToolbar\naver\search.ico
c:\program files (x86)\Naver\NaverToolbar\naver\shotcut.ico
c:\program files (x86)\Naver\NaverToolbar\naver\theme.xml
c:\program files (x86)\Naver\NaverToolbar\naver\toolbarcleaner.ico
c:\program files (x86)\Naver\NaverToolbar\naver\toolbarcleaner.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\transjapan.ico
c:\program files (x86)\Naver\NaverToolbar\naver\virus.ico
c:\program files (x86)\Naver\NaverToolbar\naver\zoom.ico
c:\program files (x86)\Naver\NaverToolbar\NaverAdminAPI.dll
c:\program files (x86)\Naver\NaverToolbar\NaverAdminAPI.exe
c:\program files (x86)\Naver\NaverToolbar\NaverTB_3_5_8_70.dll
c:\program files (x86)\Naver\NaverToolbar\NTC_1_0_0_5.exe
c:\program files (x86)\Naver\NaverToolbar\postinst.exe
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\bing_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\daum_net.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\nate_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\naver_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\paran_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\yahoo_com.xml
c:\program files (x86)\Naver\NaverToolbar\TBInfo.ini
c:\programdata\oMk06511nAiLa06511
c:\programdata\oMk06511nAiLa06511\oMk06511nAiLa06511
c:\programdata\oMk06511nAiLa06511\oMk06511nAiLa06511.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-25 do 2011-04-25 )))))))))))))))))))))))))))))))
.
.
2011-04-25 18:02 . 2011-04-25 18:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-25 15:50 . 2011-04-25 15:56 -------- d-----w- c:\users\oem\AppData\Roaming\GlarySoft
2011-04-25 15:46 . 2011-04-25 15:48 -------- d-----w- c:\program files (x86)\Glary Utilities
2011-04-25 15:31 . 2011-04-12 09:44 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-04-25 15:31 . 2011-04-12 09:44 767952 ----a-w- c:\windows\BDTSupport.dll
2011-04-25 15:31 . 2011-04-12 09:44 2074576 ----a-w- c:\windows\PCTBDCore.dll
2011-04-25 15:31 . 2011-04-12 09:44 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-04-25 15:31 . 2011-03-10 08:08 279344 ----a-w- c:\windows\system32\drivers\PCTSD64.sys
2011-04-25 15:13 . 2011-03-24 11:39 140800 ----a-w- c:\windows\system32\drivers\pctwfpfilter64.sys
2011-04-25 15:13 . 2011-01-17 08:09 334976 ----a-w- c:\windows\system32\drivers\pctgntdi64.sys
2011-04-25 15:13 . 2010-07-16 13:53 816016 ----a-w- c:\windows\system32\drivers\pctEFA64.sys
2011-04-25 15:13 . 2010-06-29 09:35 452872 ----a-w- c:\windows\system32\drivers\pctDS64.sys
2011-04-25 15:13 . 2011-03-10 09:07 282440 ----a-w- c:\windows\system32\drivers\PCTCore64.sys
2011-04-25 15:13 . 2010-12-16 06:46 92896 ----a-w- c:\windows\system32\drivers\pctplsg64.sys
2011-04-25 15:12 . 2011-04-25 15:14 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2011-04-25 15:12 . 2011-04-25 15:12 -------- d-----w- c:\users\oem\AppData\Roaming\PC Tools
2011-04-25 15:02 . 2011-04-25 15:03 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-04-25 15:02 . 2011-04-25 15:03 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-04-25 15:02 . 2011-04-25 15:03 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-04-25 11:50 . 2011-04-18 17:25 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-25 11:50 . 2011-04-18 17:17 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-25 00:19 . 2011-04-25 00:19 462848 ----a-w- c:\program files (x86)\Mozilla Firefox\null0.8460126212681808.exe
2011-04-23 16:51 . 2011-04-23 16:51 -------- d-----w- c:\users\oem\AppData\Roaming\Sahmon Games
2011-04-23 16:29 . 2011-04-23 16:51 -------- d-----w- c:\program files (x86)\PaperPlane
2011-04-23 14:37 . 2011-04-25 15:59 -------- d-----w- c:\program files (x86)\Microsoft Games
2011-04-23 13:54 . 2011-04-23 13:54 -------- d-----w- c:\users\oem\AppData\Local\Activision
2011-04-23 13:26 . 2011-04-23 13:26 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-04-23 13:26 . 2011-04-25 15:55 -------- d-----w- c:\program files (x86)\Steam
2011-04-22 12:08 . 2011-04-11 08:21 8802128 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{06E22156-BBE2-4301-85D8-DD6F08C28963}\mpengine.dll
2011-04-20 17:02 . 2011-03-18 17:55 781272 ----a-w- c:\program files (x86)\Mozilla Firefox\mozsqlite3.dll
2011-04-20 17:02 . 2011-03-18 17:55 728024 ----a-w- c:\program files (x86)\Mozilla Firefox\libGLESv2.dll
2011-04-20 17:02 . 2011-03-18 17:55 1893336 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_42.dll
2011-04-20 17:02 . 2011-03-18 17:55 1874904 ----a-w- c:\program files (x86)\Mozilla Firefox\mozjs.dll
2011-04-20 17:02 . 2011-03-18 17:55 15832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozalloc.dll
2011-04-20 17:02 . 2011-03-18 17:55 142296 ----a-w- c:\program files (x86)\Mozilla Firefox\libEGL.dll
2011-04-20 17:02 . 2011-03-18 17:55 142296 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2011-04-20 17:02 . 2011-03-18 17:55 1975768 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_42.dll
2011-04-20 14:55 . 2011-04-20 14:55 -------- d-----w- c:\users\oem\AppData\Roaming\Unity
2011-04-20 12:53 . 2011-04-20 12:53 -------- d-----w- c:\users\oem\AppData\Local\Unity
2011-04-20 10:40 . 2011-04-20 10:40 -------- d-----w- c:\users\oem\AppData\Roaming\SUPERAntiSpyware.com
2011-04-20 10:40 . 2011-04-20 10:40 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-04-20 10:40 . 2011-04-20 10:40 -------- d-----w- c:\programdata\!SASCORE
2011-04-20 10:40 . 2011-04-25 16:19 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-04-20 10:32 . 2011-04-20 10:32 -------- d-----w- c:\users\oem\AppData\Roaming\Malwarebytes
2011-04-20 10:32 . 2011-04-20 10:32 -------- d-----w- c:\programdata\Malwarebytes
2011-04-20 10:32 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-20 10:32 . 2011-04-20 10:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-20 10:32 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-20 10:15 . 2011-04-25 17:52 -------- d-----w- c:\program files (x86)\PC Tools Security
2011-04-20 10:13 . 2011-04-25 15:13 -------- d-----w- c:\programdata\PC Tools
2011-04-20 09:37 . 2011-04-20 11:34 -------- d-----w- c:\programdata\mGg06511pAnBh06511
2011-04-19 20:59 . 2011-04-19 20:59 -------- d-----w- c:\users\oem\AppData\Local\DDMSettings
2011-04-19 20:53 . 2011-03-21 13:57 173056 ----a-w- c:\windows\system32\xvid.ax
2011-04-19 20:53 . 2011-03-19 15:06 255488 ----a-w- c:\windows\system32\xvidvfw.dll
2011-04-19 20:53 . 2011-03-19 15:05 703488 ----a-w- c:\windows\system32\xvidcore.dll
2011-04-13 16:06 . 1996-05-29 02:04 4711 ----a-w- c:\windows\system32\dmouse.vxd
2011-04-13 16:06 . 2011-04-15 14:53 -------- d-----w- c:\program files\Doom Shareware for Windows 95
2011-04-13 12:09 . 2011-04-13 12:09 -------- d-----w- c:\programdata\Symantec
2011-04-13 12:09 . 2011-04-15 14:54 -------- d-----w- c:\programdata\Norton
2011-04-03 21:13 . 2011-04-12 16:59 -------- d-----w- c:\users\oem\Graphisoft
2011-04-03 21:13 . 2011-04-07 16:40 -------- d-----w- c:\users\oem\AppData\Roaming\Graphisoft
2011-04-03 21:13 . 2011-04-07 16:40 -------- d-----w- c:\users\oem\AppData\Local\Graphisoft
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\users\oem\AppData\Local\Apple
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\programdata\Apple
2011-04-03 21:08 . 2011-04-03 21:08 -------- d---a-w- c:\program files (x86)\Common Files\Graphisoft Shared
2011-04-03 21:08 . 2011-04-03 21:08 -------- d-----w- c:\program files\Graphisoft
2011-04-01 17:10 . 2009-05-12 16:13 86016 ----a-w- c:\windows\SysWow64\PortalOCP.ocx
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- C:\AMD
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- c:\programdata\ATI
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- c:\program files (x86)\AMD APP
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-04-01 17:00 . 2011-04-01 17:01 -------- d-----w- c:\program files\ATI Technologies
2011-04-01 16:59 . 2011-04-01 16:59 -------- d-----w- C:\ATI
2011-04-01 15:10 . 2011-03-23 20:10 4130616 ----a-w- c:\windows\SysWow64\GameMon.des
2011-04-01 15:04 . 2005-01-01 09:43 4682 ----a-w- c:\windows\SysWow64\npptNT2.sys
2011-04-01 15:04 . 2003-07-17 18:17 5174 ----a-w- c:\windows\SysWow64\nppt9x.vxd
2011-04-01 15:04 . 2011-04-01 15:04 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-04-01 15:02 . 2010-08-12 14:26 1443224 ----a-w- c:\windows\SysWow64\HanWebMsg1061.dll
2011-04-01 15:01 . 2010-02-17 17:53 180120 ----a-w- c:\windows\SysWow64\HGReport.dll
2011-04-01 15:01 . 2010-10-15 10:53 181424 ----a-w- c:\windows\SysWow64\PubPlugin.dll
2011-04-01 12:51 . 2011-04-01 15:04 -------- d-----w- C:\HanPurple
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-18 17:25 . 2010-10-05 21:04 40112 ----a-w- c:\windows\avastSS.scr
2011-04-18 17:25 . 2010-10-05 21:04 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-04-18 17:18 . 2010-10-05 21:05 287064 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-18 17:16 . 2010-10-05 21:05 53592 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-18 17:13 . 2010-10-05 21:05 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-18 17:13 . 2010-10-05 21:05 64344 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-18 17:13 . 2010-10-05 21:05 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-03-21 18:56 . 2011-03-21 18:56 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2011-03-21 18:56 . 2011-03-21 18:56 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-03-21 18:56 . 2011-03-21 18:56 53760 ----a-w- c:\windows\system32\OpenCL.dll
2011-03-21 18:56 . 2011-03-21 18:56 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-03-21 18:55 . 2011-03-21 18:55 16115712 ----a-w- c:\windows\system32\amdocl64.dll
2011-03-21 18:55 . 2011-03-21 18:55 12385792 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-03-15 06:50 . 2011-03-15 06:50 567152 ----a-w- c:\windows\SysWow64\NJUninst.exe
2011-02-19 06:37 . 2011-03-09 02:42 1135104 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:37 . 2011-03-09 02:42 1540608 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:36 . 2011-03-09 02:42 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32 . 2011-03-09 02:42 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 05:32 . 2011-03-09 02:42 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-02-14 22:20 . 2011-02-14 22:20 319488 ----a-w- c:\windows\HideWin.exe
2011-02-02 17:11 . 2010-08-27 17:59 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-01-26 06:53 . 2011-02-09 03:22 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-01-26 06:53 . 2011-02-09 03:22 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-26 06:31 . 2011-02-09 03:22 144384 ----a-w- c:\windows\system32\cdd.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-23 2454840]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"ISTray"="c:\program files (x86)\PC Tools Security\pctsGui.exe" [2011-04-12 1600984]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" /nogui
"ISTray"="c:\program files (x86)\PC Tools Security\pctsGui.exe" /hideGUI
"PCTools FGuard"=c:\program files (x86)\PC Tools Security\BDT\FGuard.exe
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R1 aswSnx;aswSnx; [x]
R1 aswSP;aswSP; [x]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 aswFsBlk;aswFsBlk; [x]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-04-12 337872]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2011-02-18 371472]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-10-26 124368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-04-06 258928]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-10-19 1436424]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [x]
R3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x]
S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2011-04-25 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-04-25 16:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-04-18 17:25 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-10-26 1050072]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\System32\blank.htm
uStart Page = hxxp://www.naver.com
uDefault_Search_URL = hxxp://search.qip.ru
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = www-cache.strath.ac.uk:8080
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: ??? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /SEARCH.HTML
IE: ??? ????? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /BOOKMARK.HTML
IE: ??? ??? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /BLOG.HTML
IE: ??? ?? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /DIC.HTML
IE: ??? ????? ???? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /OPENCAST.HTML
IE: ??? ?? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /JKTRANS.HTML
LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxp://mhf.hangame.com/common/activex/HanSetup1040.cab
FF - ProfilePath - c:\users\oem\AppData\Roaming\Mozilla\Firefox\Profiles\ygpahxi3.default\
FF - prefs.js: network.proxy.ftp - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-RunOnce-<NO NAME> - (no file)
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-TosReelTimeMonitor - %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TosNC - %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SmartFaceVWatcher - %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
HKLM-Run-Teco - %ProgramFiles%\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-NaverToolbar - c:\windows\system32\NJUninst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-04-25 19:04:39
ComboFix-quarantined-files.txt 2011-04-25 18:04
.
Před spuštěním: Volných bajtů: 236 607 750 144
Po spuštění: Volných bajtů: 236 419 465 216
.
- - End Of File - - 7B3A0A7CD426B6D7899FB107FBC82EA7
mám stejný poblám s MS Removal Tool, mohl bych poprosit taktéž o pomoc? Zde je log z programu ComboFix:
ComboFix 11-04-25.01 - oem 25.04.2011 18:57:31.1.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3959.3205 [GMT 1:00]
Spuštěný z: c:\users\oem\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Naver
c:\program files (x86)\Naver\NaverToolbar\DB_1_7.DAT
c:\program files (x86)\Naver\NaverToolbar\fixIE.exe
c:\program files (x86)\Naver\NaverToolbar\hangametetris\7souls.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\blog.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\bookmark.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\bookmark.JPG
c:\program files (x86)\Naver\NaverToolbar\hangametetris\bout.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\c9.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\capturebrowser.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\capturebrowser.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\cleaninternet.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\cleaninternet.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\clinic.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\config.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dic.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dicdetail.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dicdetail2.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\dictionary.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\double.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\flashgame.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gamepack.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gametalk.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gametalk.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gmahjong.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\golf.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gunster.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\gzs.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\hangamebi.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\hon.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\lasvagas.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\login.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\logo.bmp
c:\program files (x86)\Naver\NaverToolbar\hangametetris\logo.png
c:\program files (x86)\Naver\NaverToolbar\hangametetris\logout.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\magu.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\mhf.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\move.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\msduelgo.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\myblog.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\new.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\newgostop.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\opencast.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\opencast.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\pcclinic.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\Popojoy.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\popup.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\popup2.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\r2.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\real.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\search.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\seven.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\shortadr.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\shotcut.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\solitaire.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\TalesRunner.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\tera.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\tetris.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\theme.xml
c:\program files (x86)\Naver\NaverToolbar\hangametetris\toolbarcleaner.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\toolbarcleaner.jpg
c:\program files (x86)\Naver\NaverToolbar\hangametetris\transjapan.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\virus.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\yut.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\z9.ico
c:\program files (x86)\Naver\NaverToolbar\hangametetris\zoom.ico
c:\program files (x86)\Naver\NaverToolbar\InstlInfo.ini
c:\program files (x86)\Naver\NaverToolbar\juniver\artist.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\babystudy.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\blog.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\bookmark.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\bookmark.JPG
c:\program files (x86)\Naver\NaverToolbar\juniver\capturebrowser.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\capturebrowser.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\cleaninternet.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\cleaninternet.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\clinic.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\comic.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\config.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\dic.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\dicdetail.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\dicdetail2.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\dictionary.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\dongwha.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\farm_01.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\farm_02.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\flash.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gabe.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gallery.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\game.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gametalk.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\gametalk.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\homework.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\jr.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\kidsong.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\login.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\logo.bmp
c:\program files (x86)\Naver\NaverToolbar\juniver\logo.png
c:\program files (x86)\Naver\NaverToolbar\juniver\logout.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\move.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\opencast.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\opencast.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\panyroom.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\parents.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\pcclinic.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\popup.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\popup2.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\real.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\search.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\shotcut.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\theme.xml
c:\program files (x86)\Naver\NaverToolbar\juniver\toolbarcleaner.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\toolbarcleaner.jpg
c:\program files (x86)\Naver\NaverToolbar\juniver\transjapan.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\tv.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\virus.ico
c:\program files (x86)\Naver\NaverToolbar\juniver\zoom.ico
c:\program files (x86)\Naver\NaverToolbar\naver\blog.ico
c:\program files (x86)\Naver\NaverToolbar\naver\bookmark.ico
c:\program files (x86)\Naver\NaverToolbar\naver\bookmark.JPG
c:\program files (x86)\Naver\NaverToolbar\naver\capturebrowser.ico
c:\program files (x86)\Naver\NaverToolbar\naver\capturebrowser.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\cleaninternet.ico
c:\program files (x86)\Naver\NaverToolbar\naver\cleaninternet.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\clinic.ico
c:\program files (x86)\Naver\NaverToolbar\naver\config.ico
c:\program files (x86)\Naver\NaverToolbar\naver\dic.ico
c:\program files (x86)\Naver\NaverToolbar\naver\dicdetail.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\dicdetail2.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\dictionary.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\gametalk.ico
c:\program files (x86)\Naver\NaverToolbar\naver\gametalk.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\login.ico
c:\program files (x86)\Naver\NaverToolbar\naver\logo.bmp
c:\program files (x86)\Naver\NaverToolbar\naver\logo.png
c:\program files (x86)\Naver\NaverToolbar\naver\logout.ico
c:\program files (x86)\Naver\NaverToolbar\naver\move.ico
c:\program files (x86)\Naver\NaverToolbar\naver\naver.ico
c:\program files (x86)\Naver\NaverToolbar\naver\opencast.ico
c:\program files (x86)\Naver\NaverToolbar\naver\opencast.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\pcclinic.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\popup.ico
c:\program files (x86)\Naver\NaverToolbar\naver\popup2.ico
c:\program files (x86)\Naver\NaverToolbar\naver\real.ico
c:\program files (x86)\Naver\NaverToolbar\naver\search.ico
c:\program files (x86)\Naver\NaverToolbar\naver\shotcut.ico
c:\program files (x86)\Naver\NaverToolbar\naver\theme.xml
c:\program files (x86)\Naver\NaverToolbar\naver\toolbarcleaner.ico
c:\program files (x86)\Naver\NaverToolbar\naver\toolbarcleaner.jpg
c:\program files (x86)\Naver\NaverToolbar\naver\transjapan.ico
c:\program files (x86)\Naver\NaverToolbar\naver\virus.ico
c:\program files (x86)\Naver\NaverToolbar\naver\zoom.ico
c:\program files (x86)\Naver\NaverToolbar\NaverAdminAPI.dll
c:\program files (x86)\Naver\NaverToolbar\NaverAdminAPI.exe
c:\program files (x86)\Naver\NaverToolbar\NaverTB_3_5_8_70.dll
c:\program files (x86)\Naver\NaverToolbar\NTC_1_0_0_5.exe
c:\program files (x86)\Naver\NaverToolbar\postinst.exe
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\bing_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\daum_net.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\nate_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\naver_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\paran_com.xml
c:\program files (x86)\Naver\NaverToolbar\SearchEngines\yahoo_com.xml
c:\program files (x86)\Naver\NaverToolbar\TBInfo.ini
c:\programdata\oMk06511nAiLa06511
c:\programdata\oMk06511nAiLa06511\oMk06511nAiLa06511
c:\programdata\oMk06511nAiLa06511\oMk06511nAiLa06511.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-25 do 2011-04-25 )))))))))))))))))))))))))))))))
.
.
2011-04-25 18:02 . 2011-04-25 18:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-25 15:50 . 2011-04-25 15:56 -------- d-----w- c:\users\oem\AppData\Roaming\GlarySoft
2011-04-25 15:46 . 2011-04-25 15:48 -------- d-----w- c:\program files (x86)\Glary Utilities
2011-04-25 15:31 . 2011-04-12 09:44 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-04-25 15:31 . 2011-04-12 09:44 767952 ----a-w- c:\windows\BDTSupport.dll
2011-04-25 15:31 . 2011-04-12 09:44 2074576 ----a-w- c:\windows\PCTBDCore.dll
2011-04-25 15:31 . 2011-04-12 09:44 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-04-25 15:31 . 2011-03-10 08:08 279344 ----a-w- c:\windows\system32\drivers\PCTSD64.sys
2011-04-25 15:13 . 2011-03-24 11:39 140800 ----a-w- c:\windows\system32\drivers\pctwfpfilter64.sys
2011-04-25 15:13 . 2011-01-17 08:09 334976 ----a-w- c:\windows\system32\drivers\pctgntdi64.sys
2011-04-25 15:13 . 2010-07-16 13:53 816016 ----a-w- c:\windows\system32\drivers\pctEFA64.sys
2011-04-25 15:13 . 2010-06-29 09:35 452872 ----a-w- c:\windows\system32\drivers\pctDS64.sys
2011-04-25 15:13 . 2011-03-10 09:07 282440 ----a-w- c:\windows\system32\drivers\PCTCore64.sys
2011-04-25 15:13 . 2010-12-16 06:46 92896 ----a-w- c:\windows\system32\drivers\pctplsg64.sys
2011-04-25 15:12 . 2011-04-25 15:14 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2011-04-25 15:12 . 2011-04-25 15:12 -------- d-----w- c:\users\oem\AppData\Roaming\PC Tools
2011-04-25 15:02 . 2011-04-25 15:03 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-04-25 15:02 . 2011-04-25 15:03 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-04-25 15:02 . 2011-04-25 15:03 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-04-25 11:50 . 2011-04-18 17:25 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-25 11:50 . 2011-04-18 17:17 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-25 00:19 . 2011-04-25 00:19 462848 ----a-w- c:\program files (x86)\Mozilla Firefox\null0.8460126212681808.exe
2011-04-23 16:51 . 2011-04-23 16:51 -------- d-----w- c:\users\oem\AppData\Roaming\Sahmon Games
2011-04-23 16:29 . 2011-04-23 16:51 -------- d-----w- c:\program files (x86)\PaperPlane
2011-04-23 14:37 . 2011-04-25 15:59 -------- d-----w- c:\program files (x86)\Microsoft Games
2011-04-23 13:54 . 2011-04-23 13:54 -------- d-----w- c:\users\oem\AppData\Local\Activision
2011-04-23 13:26 . 2011-04-23 13:26 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-04-23 13:26 . 2011-04-25 15:55 -------- d-----w- c:\program files (x86)\Steam
2011-04-22 12:08 . 2011-04-11 08:21 8802128 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{06E22156-BBE2-4301-85D8-DD6F08C28963}\mpengine.dll
2011-04-20 17:02 . 2011-03-18 17:55 781272 ----a-w- c:\program files (x86)\Mozilla Firefox\mozsqlite3.dll
2011-04-20 17:02 . 2011-03-18 17:55 728024 ----a-w- c:\program files (x86)\Mozilla Firefox\libGLESv2.dll
2011-04-20 17:02 . 2011-03-18 17:55 1893336 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_42.dll
2011-04-20 17:02 . 2011-03-18 17:55 1874904 ----a-w- c:\program files (x86)\Mozilla Firefox\mozjs.dll
2011-04-20 17:02 . 2011-03-18 17:55 15832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozalloc.dll
2011-04-20 17:02 . 2011-03-18 17:55 142296 ----a-w- c:\program files (x86)\Mozilla Firefox\libEGL.dll
2011-04-20 17:02 . 2011-03-18 17:55 142296 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2011-04-20 17:02 . 2011-03-18 17:55 1975768 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_42.dll
2011-04-20 14:55 . 2011-04-20 14:55 -------- d-----w- c:\users\oem\AppData\Roaming\Unity
2011-04-20 12:53 . 2011-04-20 12:53 -------- d-----w- c:\users\oem\AppData\Local\Unity
2011-04-20 10:40 . 2011-04-20 10:40 -------- d-----w- c:\users\oem\AppData\Roaming\SUPERAntiSpyware.com
2011-04-20 10:40 . 2011-04-20 10:40 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-04-20 10:40 . 2011-04-20 10:40 -------- d-----w- c:\programdata\!SASCORE
2011-04-20 10:40 . 2011-04-25 16:19 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-04-20 10:32 . 2011-04-20 10:32 -------- d-----w- c:\users\oem\AppData\Roaming\Malwarebytes
2011-04-20 10:32 . 2011-04-20 10:32 -------- d-----w- c:\programdata\Malwarebytes
2011-04-20 10:32 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-20 10:32 . 2011-04-20 10:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-20 10:32 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-20 10:15 . 2011-04-25 17:52 -------- d-----w- c:\program files (x86)\PC Tools Security
2011-04-20 10:13 . 2011-04-25 15:13 -------- d-----w- c:\programdata\PC Tools
2011-04-20 09:37 . 2011-04-20 11:34 -------- d-----w- c:\programdata\mGg06511pAnBh06511
2011-04-19 20:59 . 2011-04-19 20:59 -------- d-----w- c:\users\oem\AppData\Local\DDMSettings
2011-04-19 20:53 . 2011-03-21 13:57 173056 ----a-w- c:\windows\system32\xvid.ax
2011-04-19 20:53 . 2011-03-19 15:06 255488 ----a-w- c:\windows\system32\xvidvfw.dll
2011-04-19 20:53 . 2011-03-19 15:05 703488 ----a-w- c:\windows\system32\xvidcore.dll
2011-04-13 16:06 . 1996-05-29 02:04 4711 ----a-w- c:\windows\system32\dmouse.vxd
2011-04-13 16:06 . 2011-04-15 14:53 -------- d-----w- c:\program files\Doom Shareware for Windows 95
2011-04-13 12:09 . 2011-04-13 12:09 -------- d-----w- c:\programdata\Symantec
2011-04-13 12:09 . 2011-04-15 14:54 -------- d-----w- c:\programdata\Norton
2011-04-03 21:13 . 2011-04-12 16:59 -------- d-----w- c:\users\oem\Graphisoft
2011-04-03 21:13 . 2011-04-07 16:40 -------- d-----w- c:\users\oem\AppData\Roaming\Graphisoft
2011-04-03 21:13 . 2011-04-07 16:40 -------- d-----w- c:\users\oem\AppData\Local\Graphisoft
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\users\oem\AppData\Local\Apple
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-04-03 21:11 . 2011-04-03 21:11 -------- d-----w- c:\programdata\Apple
2011-04-03 21:08 . 2011-04-03 21:08 -------- d---a-w- c:\program files (x86)\Common Files\Graphisoft Shared
2011-04-03 21:08 . 2011-04-03 21:08 -------- d-----w- c:\program files\Graphisoft
2011-04-01 17:10 . 2009-05-12 16:13 86016 ----a-w- c:\windows\SysWow64\PortalOCP.ocx
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- C:\AMD
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- c:\programdata\ATI
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- c:\program files (x86)\AMD APP
2011-04-01 17:01 . 2011-04-01 17:01 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-04-01 17:00 . 2011-04-01 17:01 -------- d-----w- c:\program files\ATI Technologies
2011-04-01 16:59 . 2011-04-01 16:59 -------- d-----w- C:\ATI
2011-04-01 15:10 . 2011-03-23 20:10 4130616 ----a-w- c:\windows\SysWow64\GameMon.des
2011-04-01 15:04 . 2005-01-01 09:43 4682 ----a-w- c:\windows\SysWow64\npptNT2.sys
2011-04-01 15:04 . 2003-07-17 18:17 5174 ----a-w- c:\windows\SysWow64\nppt9x.vxd
2011-04-01 15:04 . 2011-04-01 15:04 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-04-01 15:02 . 2010-08-12 14:26 1443224 ----a-w- c:\windows\SysWow64\HanWebMsg1061.dll
2011-04-01 15:01 . 2010-02-17 17:53 180120 ----a-w- c:\windows\SysWow64\HGReport.dll
2011-04-01 15:01 . 2010-10-15 10:53 181424 ----a-w- c:\windows\SysWow64\PubPlugin.dll
2011-04-01 12:51 . 2011-04-01 15:04 -------- d-----w- C:\HanPurple
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-18 17:25 . 2010-10-05 21:04 40112 ----a-w- c:\windows\avastSS.scr
2011-04-18 17:25 . 2010-10-05 21:04 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-04-18 17:18 . 2010-10-05 21:05 287064 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-18 17:16 . 2010-10-05 21:05 53592 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-18 17:13 . 2010-10-05 21:05 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-18 17:13 . 2010-10-05 21:05 64344 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-18 17:13 . 2010-10-05 21:05 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-03-21 18:56 . 2011-03-21 18:56 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2011-03-21 18:56 . 2011-03-21 18:56 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-03-21 18:56 . 2011-03-21 18:56 53760 ----a-w- c:\windows\system32\OpenCL.dll
2011-03-21 18:56 . 2011-03-21 18:56 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-03-21 18:55 . 2011-03-21 18:55 16115712 ----a-w- c:\windows\system32\amdocl64.dll
2011-03-21 18:55 . 2011-03-21 18:55 12385792 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-03-15 06:50 . 2011-03-15 06:50 567152 ----a-w- c:\windows\SysWow64\NJUninst.exe
2011-02-19 06:37 . 2011-03-09 02:42 1135104 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:37 . 2011-03-09 02:42 1540608 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:36 . 2011-03-09 02:42 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32 . 2011-03-09 02:42 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 05:32 . 2011-03-09 02:42 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-02-14 22:20 . 2011-02-14 22:20 319488 ----a-w- c:\windows\HideWin.exe
2011-02-02 17:11 . 2010-08-27 17:59 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-01-26 06:53 . 2011-02-09 03:22 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-01-26 06:53 . 2011-02-09 03:22 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-26 06:31 . 2011-02-09 03:22 144384 ----a-w- c:\windows\system32\cdd.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-23 2454840]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"ISTray"="c:\program files (x86)\PC Tools Security\pctsGui.exe" [2011-04-12 1600984]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" /nogui
"ISTray"="c:\program files (x86)\PC Tools Security\pctsGui.exe" /hideGUI
"PCTools FGuard"=c:\program files (x86)\PC Tools Security\BDT\FGuard.exe
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R1 aswSnx;aswSnx; [x]
R1 aswSP;aswSP; [x]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [x]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 aswFsBlk;aswFsBlk; [x]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-04-12 337872]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2011-02-18 371472]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-10-26 124368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-04-06 258928]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-10-19 1436424]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [x]
R3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x]
S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2011-04-25 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-04-25 16:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-04-18 17:25 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-10-26 1050072]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\System32\blank.htm
uStart Page = hxxp://www.naver.com
uDefault_Search_URL = hxxp://search.qip.ru
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = www-cache.strath.ac.uk:8080
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: ??? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /SEARCH.HTML
IE: ??? ????? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /BOOKMARK.HTML
IE: ??? ??? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /BLOG.HTML
IE: ??? ?? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /DIC.HTML
IE: ??? ????? ???? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /OPENCAST.HTML
IE: ??? ?? ?? - c:\program files (x86)\naver\NaverToolbar\NaverTB_3_5_8_70.dll /JKTRANS.HTML
LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxp://mhf.hangame.com/common/activex/HanSetup1040.cab
FF - ProfilePath - c:\users\oem\AppData\Roaming\Mozilla\Firefox\Profiles\ygpahxi3.default\
FF - prefs.js: network.proxy.ftp - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - www-cache.strath.ac.uk
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-RunOnce-<NO NAME> - (no file)
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-TosReelTimeMonitor - %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TosNC - %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SmartFaceVWatcher - %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
HKLM-Run-Teco - %ProgramFiles%\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-NaverToolbar - c:\windows\system32\NJUninst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-04-25 19:04:39
ComboFix-quarantined-files.txt 2011-04-25 18:04
.
Před spuštěním: Volných bajtů: 236 607 750 144
Po spuštění: Volných bajtů: 236 419 465 216
.
- - End Of File - - 7B3A0A7CD426B6D7899FB107FBC82EA7