Prosím kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

BiScHop
Level 3
Level 3
Příspěvky: 591
Registrován: leden 09
Bydliště: Děčín
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu

Příspěvekod BiScHop » 29 črc 2011 14:38

ComboFix 11-07-26.02 - Mrožík 29.07.2011 12:04:29.6.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2871.1245 [GMT 2:00]
Spuštěný z: c:\users\Mro×Ýk\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Mro×Ýk\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-28 do 2011-07-29 )))))))))))))))))))))))))))))))
.
.
2011-07-29 10:17 . 2011-07-29 10:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-28 22:27 . 2011-07-28 22:29 -------- d-----w- c:\program files (x86)\Google
2011-07-28 19:57 . 2011-07-28 19:57 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Avira
2011-07-28 19:43 . 2011-06-17 10:37 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-07-28 19:43 . 2011-06-17 10:37 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-07-28 19:43 . 2011-07-28 19:43 -------- d-----w- c:\programdata\Avira
2011-07-28 19:43 . 2011-07-28 19:43 -------- d-----w- c:\program files (x86)\Avira
2011-07-28 17:33 . 2009-09-10 12:54 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-28 17:33 . 2011-07-28 17:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-26 09:05 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CB199826-B008-4107-931B-0A6D717AC9C1}\mpengine.dll
2011-07-25 23:43 . 2011-07-25 23:43 -------- d-----w- c:\program files (x86)\trend micro
2011-07-25 23:43 . 2011-07-25 23:44 -------- d-----w- C:\rsit
2011-07-21 23:42 . 2011-07-21 23:42 -------- d-----w- c:\programdata\ATI
2011-07-21 23:35 . 2011-07-21 23:35 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-07-21 23:33 . 2011-07-21 23:36 -------- d-----w- c:\program files\ATI Technologies
2011-07-21 23:03 . 2011-07-21 23:03 -------- d-----w- c:\users\Mrožík\AppData\Local\uTorrent
2011-07-21 23:03 . 2011-07-21 23:15 -------- d-----w- c:\users\Mrožík\AppData\Roaming\BitTorrent
2011-07-21 22:31 . 2011-07-21 22:31 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-07-21 22:30 . 2011-07-21 23:41 -------- d-----w- c:\program files (x86)\Steam
2011-07-15 08:32 . 2011-07-15 08:32 -------- d-----w- c:\users\Mrožík\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-07-15 08:32 . 2011-07-15 08:32 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Adobe Mini Bridge CS5
2011-07-14 00:35 . 2011-07-14 00:35 -------- d-sha-w- c:\users\Public\DRM
2011-07-14 00:15 . 2011-07-14 00:15 -------- d-----w- c:\program files\BreakPoint Software
2011-07-14 00:02 . 2011-07-14 00:02 -------- d-----w- c:\users\Mrožík\AppData\Local\Rockstar Games
2011-07-14 00:01 . 2011-07-14 00:01 -------- d-sh--w- c:\programdata\SecuROM
2011-07-13 23:52 . 2010-02-15 10:03 286208 ----a-w- c:\windows\SysWow64\binkw32.dll
2011-07-13 23:42 . 2011-07-13 23:59 -------- d-----w- c:\program files (x86)\Rockstar Games
2011-07-13 22:44 . 2011-07-13 22:44 -------- d-----w- c:\windows\SysWow64\xlive
2011-07-13 22:44 . 2011-07-14 22:29 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2011-07-13 22:11 . 2011-07-13 22:11 -------- d--h--r- c:\users\Mrožík\AppData\Roaming\SecuROM
2011-07-13 22:01 . 2011-07-13 22:01 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2011-07-13 20:48 . 2011-07-13 20:48 -------- d-----w- c:\users\Mrožík\AppData\Roaming\com.bigfatsimulations.airportmadness3.3A85083A650345D1ADAB4572C5816AD2DC9802A3.1
2011-07-13 20:18 . 2011-07-13 20:18 3789728 ----a-w- c:\windows\SysWow64\Flash.ocx
2011-07-13 17:48 . 2011-06-02 06:39 422400 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 17:27 . 2011-04-28 03:58 552448 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-13 17:27 . 2011-04-28 03:58 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-13 17:27 . 2011-06-11 02:56 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-07-10 21:05 . 2011-07-10 21:05 -------- d-----w- C:\ATI
2011-07-10 20:50 . 2011-07-10 20:50 -------- d-----w- c:\program files (x86)\directx
2011-07-10 19:03 . 2011-07-13 21:27 -------- d-----w- c:\users\Mrožík\AppData\Roaming\vlc
2011-07-10 19:02 . 2011-07-10 19:02 -------- d-----w- c:\program files (x86)\VideoLAN
2011-07-04 17:49 . 2011-07-04 17:49 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Publish Providers
2011-07-04 17:49 . 2011-07-04 17:49 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Sony
2011-07-04 17:49 . 2011-07-04 17:49 -------- d-----w- c:\users\Mrožík\AppData\Local\Sony
2011-07-04 17:43 . 2011-07-04 17:43 -------- d-----w- c:\program files (x86)\Vstplugins
2011-07-04 17:43 . 2011-07-04 17:43 -------- d-----w- c:\programdata\Sony
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-24 10:58 . 2011-06-22 23:20 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-06-02 05:56 . 2011-07-13 17:50 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 03:25 . 2011-06-18 10:26 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 03:00 . 2011-06-18 10:26 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-24 21:44 . 2011-05-24 21:44 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2011-05-24 21:44 . 2011-05-24 21:44 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-05-24 21:44 . 2011-05-24 21:44 53760 ----a-w- c:\windows\system32\OpenCL.dll
2011-05-24 21:44 . 2011-05-24 21:44 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-05-24 21:44 . 2011-05-24 21:44 16672768 ----a-w- c:\windows\system32\amdocl64.dll
2011-05-24 21:43 . 2011-05-24 21:43 12798976 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-05-24 17:14 . 2011-04-09 16:34 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 11:21 . 2011-06-29 08:14 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-29 08:14 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-29 08:14 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-29 08:14 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-29 08:14 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-05-04 05:30 . 2011-06-29 08:14 2326016 ----a-w- c:\windows\system32\tquery.dll
2011-05-04 05:28 . 2011-06-29 08:14 2228224 ----a-w- c:\windows\system32\mssrch.dll
2011-05-04 05:28 . 2011-06-29 08:14 779264 ----a-w- c:\windows\system32\mssvp.dll
2011-05-04 05:28 . 2011-06-29 08:14 491520 ----a-w- c:\windows\system32\mssph.dll
2011-05-04 05:28 . 2011-06-29 08:14 75264 ----a-w- c:\windows\system32\msscntrs.dll
2011-05-04 05:28 . 2011-06-29 08:14 288256 ----a-w- c:\windows\system32\mssphtb.dll
2011-05-04 05:24 . 2011-06-29 08:14 593408 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-05-04 05:24 . 2011-06-29 08:14 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-05-04 05:24 . 2011-06-29 08:14 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-05-04 04:53 . 2011-06-29 08:14 1553920 ----a-w- c:\windows\SysWow64\tquery.dll
2011-05-04 04:52 . 2011-06-29 08:14 1401856 ----a-w- c:\windows\SysWow64\mssrch.dll
2011-05-04 04:52 . 2011-06-29 08:14 666624 ----a-w- c:\windows\SysWow64\mssvp.dll
2011-05-04 04:52 . 2011-06-29 08:14 337408 ----a-w- c:\windows\SysWow64\mssph.dll
2011-05-04 04:52 . 2011-06-29 08:14 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll
2011-05-04 04:52 . 2011-06-29 08:14 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll
2011-05-04 04:52 . 2011-06-29 08:14 428032 ----a-w- c:\windows\SysWow64\SearchIndexer.exe
2011-05-04 04:52 . 2011-06-29 08:14 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe
2011-05-04 04:52 . 2011-06-29 08:14 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe
2011-05-04 02:51 . 2011-06-18 10:27 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-05-04 02:51 . 2011-06-18 10:27 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-05-04 02:51 . 2011-06-18 10:27 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-05-03 05:21 . 2011-06-18 10:26 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:50 . 2011-06-18 10:26 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-07-29_06.03.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 05:30 . 2011-07-28 22:00 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-07-29 09:58 86016 c:\windows\system32\DriverStore\infpub.dat
- 2011-04-09 18:21 . 2011-07-29 05:06 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-04-09 18:21 . 2011-07-29 10:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-04-09 18:21 . 2011-07-29 05:06 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-04-09 18:21 . 2011-07-29 10:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-04-11 05:31 . 2011-07-29 09:58 350998 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 05:30 . 2011-07-29 09:58 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-07-28 22:00 143360 c:\windows\system32\DriverStore\infstrng.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"NokiaOviSuite2"="c:\program files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-05-20 724536]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696]
"GIGABYTEMOUSE"="c:\program files (x86)\GIGABYTE\GIGABYTE Sim Series7\Mouse.exe" [2009-11-26 1278464]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-21 98304]
"Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"NI Background Service"=c:\program files (x86)\National Instruments\Shared\Update Service\BackgroundService.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 136176]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-04-09 1038088]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 136176]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\mrožík\Programy\Microsoft Office 2010\Office14\GROOVE.EXE [2010-03-25 51456888]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
R4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R4 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-03-03 325200]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2010-04-23 820768]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
S2 ODDPwrSvc;Acer ODD Power Service;c:\program files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [2010-04-22 171040]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-03-30 2026304]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-02-10 11856]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 22:27]
.
2011-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 22:27]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2010-04-23 496160]
"ODDPwr"="c:\program files\Acer\Optical Drive Power Management\ODDPwr.exe" [2010-04-22 223264]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-22 10775072]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-04-22 2040352]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-20 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-20 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-20 413720]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\mrožík\Programy\Fences\FencesMenu64.dll" [2010-06-22 253288]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\mrok~1\Programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\mrok~1\Programy\MICROS~1\Office14\ONBttnIE.dll/105
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 100.100.100.100
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2843318325-4272059421-2341105498-1000\Software\SecuROM\License information*]
"datasecu"=hex:6d,91,f3,33,f9,68,f4,a6,2c,0e,b9,82,62,b8,ab,94,0e,2d,79,d5,f3,
c5,cf,42,c1,8c,71,81,e2,0b,31,9b,37,8e,ec,03,34,e3,c3,cc,d8,f1,65,e8,49,4f,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
Celkový čas: 2011-07-29 12:35:59
ComboFix-quarantined-files.txt 2011-07-29 10:35
ComboFix2.txt 2011-07-29 06:06
ComboFix3.txt 2011-07-28 18:52
ComboFix4.txt 2011-07-26 17:48
ComboFix5.txt 2011-07-29 10:03
.
Před spuštěním: Volných bajtů: 44 458 995 712
Po spuštění: Volných bajtů: 44 378 550 272
.
- - End Of File - - 837CB51C57AAC0C0F6678628615C802E

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím kontrolu

Příspěvekod memphisto » 29 črc 2011 15:17

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"=-
"ConsentPromptBehaviorAdmin"=-
"PromptOnSecureDesktop"=-

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

DDS::
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

BiScHop
Level 3
Level 3
Příspěvky: 591
Registrován: leden 09
Bydliště: Děčín
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu

Příspěvekod BiScHop » 29 črc 2011 16:50

ComboFix 11-07-26.02 - Mrožík 29.07.2011 16:17:03.7.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2871.1293 [GMT 2:00]
Spuštěný z: c:\users\Mro×Ýk\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Mro×Ýk\Desktop\CFScript.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-28 do 2011-07-29 )))))))))))))))))))))))))))))))
.
.
2011-07-29 14:29 . 2011-07-29 14:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-28 22:27 . 2011-07-28 22:29 -------- d-----w- c:\program files (x86)\Google
2011-07-28 19:57 . 2011-07-28 19:57 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Avira
2011-07-28 19:43 . 2011-06-17 10:37 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-07-28 19:43 . 2011-06-17 10:37 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-07-28 19:43 . 2011-07-28 19:43 -------- d-----w- c:\programdata\Avira
2011-07-28 19:43 . 2011-07-28 19:43 -------- d-----w- c:\program files (x86)\Avira
2011-07-28 17:33 . 2009-09-10 12:54 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-28 17:33 . 2011-07-28 17:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-26 09:05 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CB199826-B008-4107-931B-0A6D717AC9C1}\mpengine.dll
2011-07-25 23:43 . 2011-07-25 23:43 -------- d-----w- c:\program files (x86)\trend micro
2011-07-25 23:43 . 2011-07-25 23:44 -------- d-----w- C:\rsit
2011-07-21 23:42 . 2011-07-21 23:42 -------- d-----w- c:\programdata\ATI
2011-07-21 23:35 . 2011-07-21 23:35 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-07-21 23:33 . 2011-07-21 23:36 -------- d-----w- c:\program files\ATI Technologies
2011-07-21 23:03 . 2011-07-21 23:03 -------- d-----w- c:\users\Mrožík\AppData\Local\uTorrent
2011-07-21 23:03 . 2011-07-21 23:15 -------- d-----w- c:\users\Mrožík\AppData\Roaming\BitTorrent
2011-07-21 22:31 . 2011-07-21 22:31 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-07-21 22:30 . 2011-07-21 23:41 -------- d-----w- c:\program files (x86)\Steam
2011-07-15 08:32 . 2011-07-15 08:32 -------- d-----w- c:\users\Mrožík\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-07-15 08:32 . 2011-07-15 08:32 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Adobe Mini Bridge CS5
2011-07-14 00:35 . 2011-07-14 00:35 -------- d-sha-w- c:\users\Public\DRM
2011-07-14 00:15 . 2011-07-14 00:15 -------- d-----w- c:\program files\BreakPoint Software
2011-07-14 00:02 . 2011-07-14 00:02 -------- d-----w- c:\users\Mrožík\AppData\Local\Rockstar Games
2011-07-14 00:01 . 2011-07-14 00:01 -------- d-sh--w- c:\programdata\SecuROM
2011-07-13 23:52 . 2010-02-15 10:03 286208 ----a-w- c:\windows\SysWow64\binkw32.dll
2011-07-13 23:42 . 2011-07-13 23:59 -------- d-----w- c:\program files (x86)\Rockstar Games
2011-07-13 22:44 . 2011-07-13 22:44 -------- d-----w- c:\windows\SysWow64\xlive
2011-07-13 22:44 . 2011-07-14 22:29 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2011-07-13 22:11 . 2011-07-13 22:11 -------- d--h--r- c:\users\Mrožík\AppData\Roaming\SecuROM
2011-07-13 22:01 . 2011-07-13 22:01 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2011-07-13 20:48 . 2011-07-13 20:48 -------- d-----w- c:\users\Mrožík\AppData\Roaming\com.bigfatsimulations.airportmadness3.3A85083A650345D1ADAB4572C5816AD2DC9802A3.1
2011-07-13 20:18 . 2011-07-13 20:18 3789728 ----a-w- c:\windows\SysWow64\Flash.ocx
2011-07-13 17:48 . 2011-06-02 06:39 422400 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 17:27 . 2011-04-28 03:58 552448 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-13 17:27 . 2011-04-28 03:58 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-13 17:27 . 2011-06-11 02:56 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-07-10 21:05 . 2011-07-10 21:05 -------- d-----w- C:\ATI
2011-07-10 20:50 . 2011-07-10 20:50 -------- d-----w- c:\program files (x86)\directx
2011-07-10 19:03 . 2011-07-13 21:27 -------- d-----w- c:\users\Mrožík\AppData\Roaming\vlc
2011-07-10 19:02 . 2011-07-10 19:02 -------- d-----w- c:\program files (x86)\VideoLAN
2011-07-04 17:49 . 2011-07-04 17:49 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Publish Providers
2011-07-04 17:49 . 2011-07-04 17:49 -------- d-----w- c:\users\Mrožík\AppData\Roaming\Sony
2011-07-04 17:49 . 2011-07-04 17:49 -------- d-----w- c:\users\Mrožík\AppData\Local\Sony
2011-07-04 17:43 . 2011-07-04 17:43 -------- d-----w- c:\program files (x86)\Vstplugins
2011-07-04 17:43 . 2011-07-04 17:43 -------- d-----w- c:\programdata\Sony
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-24 10:58 . 2011-06-22 23:20 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-06-02 05:56 . 2011-07-13 17:50 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 03:25 . 2011-06-18 10:26 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-28 03:00 . 2011-06-18 10:26 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-05-24 21:44 . 2011-05-24 21:44 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2011-05-24 21:44 . 2011-05-24 21:44 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-05-24 21:44 . 2011-05-24 21:44 53760 ----a-w- c:\windows\system32\OpenCL.dll
2011-05-24 21:44 . 2011-05-24 21:44 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-05-24 21:44 . 2011-05-24 21:44 16672768 ----a-w- c:\windows\system32\amdocl64.dll
2011-05-24 21:43 . 2011-05-24 21:43 12798976 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-05-24 17:14 . 2011-04-09 16:34 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 11:21 . 2011-06-29 08:14 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-29 08:14 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-29 08:14 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-29 08:14 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-29 08:14 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-05-04 05:30 . 2011-06-29 08:14 2326016 ----a-w- c:\windows\system32\tquery.dll
2011-05-04 05:28 . 2011-06-29 08:14 2228224 ----a-w- c:\windows\system32\mssrch.dll
2011-05-04 05:28 . 2011-06-29 08:14 779264 ----a-w- c:\windows\system32\mssvp.dll
2011-05-04 05:28 . 2011-06-29 08:14 491520 ----a-w- c:\windows\system32\mssph.dll
2011-05-04 05:28 . 2011-06-29 08:14 75264 ----a-w- c:\windows\system32\msscntrs.dll
2011-05-04 05:28 . 2011-06-29 08:14 288256 ----a-w- c:\windows\system32\mssphtb.dll
2011-05-04 05:24 . 2011-06-29 08:14 593408 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-05-04 05:24 . 2011-06-29 08:14 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-05-04 05:24 . 2011-06-29 08:14 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-05-04 04:53 . 2011-06-29 08:14 1553920 ----a-w- c:\windows\SysWow64\tquery.dll
2011-05-04 04:52 . 2011-06-29 08:14 1401856 ----a-w- c:\windows\SysWow64\mssrch.dll
2011-05-04 04:52 . 2011-06-29 08:14 666624 ----a-w- c:\windows\SysWow64\mssvp.dll
2011-05-04 04:52 . 2011-06-29 08:14 337408 ----a-w- c:\windows\SysWow64\mssph.dll
2011-05-04 04:52 . 2011-06-29 08:14 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll
2011-05-04 04:52 . 2011-06-29 08:14 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll
2011-05-04 04:52 . 2011-06-29 08:14 428032 ----a-w- c:\windows\SysWow64\SearchIndexer.exe
2011-05-04 04:52 . 2011-06-29 08:14 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe
2011-05-04 04:52 . 2011-06-29 08:14 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe
2011-05-04 02:51 . 2011-06-18 10:27 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-05-04 02:51 . 2011-06-18 10:27 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-05-04 02:51 . 2011-06-18 10:27 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-05-03 05:21 . 2011-06-18 10:26 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:50 . 2011-06-18 10:26 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-07-29_06.03.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 05:30 . 2011-07-28 22:00 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-07-29 12:32 86016 c:\windows\system32\DriverStore\infpub.dat
- 2011-04-09 18:21 . 2011-07-29 05:06 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-04-09 18:21 . 2011-07-29 14:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-04-09 18:21 . 2011-07-29 05:06 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-04-09 18:21 . 2011-07-29 14:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-04-11 05:31 . 2011-07-29 09:58 350998 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 05:30 . 2011-07-29 12:32 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-07-28 22:00 143360 c:\windows\system32\DriverStore\infstrng.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"NokiaOviSuite2"="c:\program files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-05-20 724536]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696]
"GIGABYTEMOUSE"="c:\program files (x86)\GIGABYTE\GIGABYTE Sim Series7\Mouse.exe" [2009-11-26 1278464]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-21 98304]
"Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"NI Background Service"=c:\program files (x86)\National Instruments\Shared\Update Service\BackgroundService.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 136176]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-04-09 1038088]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 136176]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\mrožík\Programy\Microsoft Office 2010\Office14\GROOVE.EXE [2010-03-25 51456888]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
R4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R4 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-03-03 325200]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2010-04-23 820768]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
S2 ODDPwrSvc;Acer ODD Power Service;c:\program files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [2010-04-22 171040]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-03-30 2026304]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2314240]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-02-10 11856]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 22:27]
.
2011-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 22:27]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2010-04-23 496160]
"ODDPwr"="c:\program files\Acer\Optical Drive Power Management\ODDPwr.exe" [2010-04-22 223264]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-22 10775072]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-04-22 2040352]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-20 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-20 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-20 413720]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\mrožík\Programy\Fences\FencesMenu64.dll" [2010-06-22 253288]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\mrok~1\Programy\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\mrok~1\Programy\MICROS~1\Office14\ONBttnIE.dll/105
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 100.100.100.100
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2843318325-4272059421-2341105498-1000\Software\SecuROM\License information*]
"datasecu"=hex:6d,91,f3,33,f9,68,f4,a6,2c,0e,b9,82,62,b8,ab,94,0e,2d,79,d5,f3,
c5,cf,42,c1,8c,71,81,e2,0b,31,9b,37,8e,ec,03,34,e3,c3,cc,d8,f1,65,e8,49,4f,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
Celkový čas: 2011-07-29 16:49:19
ComboFix-quarantined-files.txt 2011-07-29 14:49
ComboFix2.txt 2011-07-29 10:36
ComboFix3.txt 2011-07-29 06:06
ComboFix4.txt 2011-07-28 18:52
ComboFix5.txt 2011-07-29 14:15
.
Před spuštěním: Volných bajtů: 44 454 916 096
Po spuštění: Volných bajtů: 43 398 545 408
.
- - End Of File - - 96FBCD42BC3EFB268E5035DEC30F645A

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím kontrolu  Vyřešeno

Příspěvekod jaro3 » 29 črc 2011 21:36

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vyčisti systém CCleanerem

a použij i T-Cleaner

http://www.edisk.cz/stahni/29485/T-Clea ... 8.5KB.html

smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj antivir a antispyware ,následně T-Cleaner smaž a zapni si znovu antivir a antispyware.

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 104 hostů