ComboFix 14-06-13.01 - Kridas 14.06.2014 8:03.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.7645.6121 [GMT 2:00]
Spuštěný z: c:\users\Kridas\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Kridas\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA1ce78d0b9cc9824.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateComRegisterShell64.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.24.7\goopdate.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.24.7\psmachine.dll
c:\program files (x86)\Google\Update\1.3.24.7\psmachine_64.dll
c:\program files (x86)\Google\Update\1.3.24.7\psuser.dll
c:\program files (x86)\Google\Update\1.3.24.7\psuser_64.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.24.7\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\35.0.1916.153\35.0.1916.153_35.0.1916.114_chrome_updater_alt.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA1ce78d0b9cc9824.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-05-14 do 2014-06-14 )))))))))))))))))))))))))))))))
.
.
2014-06-08 10:03 . 2014-06-08 10:03 -------- d-----w- c:\programdata\RogueKiller
2014-06-08 08:47 . 2014-06-08 08:47 -------- d-----w- c:\users\Kridas\AppData\Local\SniperV2
2014-06-07 08:55 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-06 17:40 . 2014-06-06 17:41 -------- d-----w- c:\program files (x86)\CheckPoint
2014-06-06 17:40 . 2014-06-06 17:40 -------- d-----w- c:\programdata\CheckPoint
2014-05-30 00:35 . 2014-05-30 00:35 450968 ----a-w- c:\windows\system32\drivers\vsdatant.sys
2014-05-23 17:13 . 2014-05-24 10:42 -------- d-----w- c:\program files (x86)\Battle.net
2014-05-20 11:55 . 2014-05-20 12:01 -------- d-----w- c:\programdata\BlueStacksSetup
2014-05-18 06:34 . 2014-05-18 06:34 -------- d-----w- c:\program files (x86)\Electronic Arts
2014-05-17 19:45 . 2014-05-17 19:47 -------- d-----w- c:\program files (x86)\Postal2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-03 13:02 . 2013-09-21 05:53 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-06-03 13:02 . 2013-09-21 05:53 112080 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-05-08 04:45 . 2013-03-15 15:26 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-08 04:45 . 2013-03-15 15:26 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-26 10:46 . 2013-12-16 19:46 291760 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-04-26 10:46 . 2013-07-23 19:29 291760 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-04-26 10:43 . 2013-07-23 19:29 291488 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-04-23 10:32 . 2013-07-23 19:29 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-04-14 18:13 . 2014-04-17 07:31 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-01-08 3674320]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2014-01-17 759496]
"GarenaPlus"="c:\users\Kridas\Garena Plus\GarenaMessenger.exe" [2014-04-29 9936176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-05-04 630912]
"Super-Charger"="c:\program files (x86)\MSI\Super-Charger\Super-Charger.exe" [2012-07-27 495616]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-06-03 737872]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2014-05-30 137352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\users\Kridas\Garena Plus\Room\safedrv.sys;c:\users\Kridas\Garena Plus\Room\safedrv.sys [x]
R3 MSICDSetup;MSICDSetup;e:\cdriver64.sys;e:\CDriver64.sys [x]
R3 NTIOLib_1_0_C;NTIOLib_1_0_C;e:\ntiolib_x64.sys;e:\NTIOLib_X64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 MSI_SuperCharger;MSI_SuperCharger;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 ZAPrivacyService;ZoneAlarm Privacy Service;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe;c:\program files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [x]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-13 13:06 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-06-12 6548112]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
hxxp://search.yahoo.com/?fr=avantsearch6mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Kridas\AppData\Roaming\Mozilla\Firefox\Profiles\isixggdg.default\
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3594707305-2944351020-577977710-1000\Software\SecuROM\License information*]
"datasecu"=hex:f7,31,50,2e,d1,5e,ec,1d,b0,da,68,a9,c4,9a,13,ff,46,af,f5,fb,b1,
66,34,f9,ad,73,99,ea,9a,de,e1,ae,29,d0,93,fe,82,18,96,68,a6,84,a8,a2,e0,d7,\
"rkeysecu"=hex:a6,30,32,fc,23,4b,6b,f7,7b,a3,83,8c,6a,13,bc,80
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\users\Kridas\Garena Plus\ggdllhost.exe
.
**************************************************************************
.
Celkový čas: 2014-06-14 08:16:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-06-14 06:16
ComboFix2.txt 2014-06-12 14:08
ComboFix3.txt 2014-06-11 12:16
.
Před spuštěním: Volných bajtů: 23 709 880 320
Po spuštění: Volných bajtů: 23 337 197 568
.
- - End Of File - - BCF8E7F00649346828DD8179665092A0
A36C5E4F47E84449FF07ED3517B43A31