Je možné, aby se mi nějaký číňan hrabal v PC? +log Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Clorky » 29 lis 2012 18:37

Pardon, tady je:
ComboFix 12-11-29.02 - Petr 29.11.2012 15:38:23.4.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.8190.6323 [GMT 1:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\users\Petr\AppData\Local\Temp\sfamcc00001.dll
c:\users\Petr\AppData\Local\Temp\sfareca00001.dll
.
Nakažená kopie c:\windows\System32\autoconv.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-convert_31bf3856ad364e35_6.1.7601.17514_none_fafb502abef1be40\autoconv.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-28 do 2012-11-29 )))))))))))))))))))))))))))))))
.
.
2012-11-29 14:40 . 2012-11-29 14:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-28 21:02 . 2012-11-28 21:02 -------- d-----w- c:\users\Petr\AppData\Local\Chromium
2012-11-28 21:01 . 2012-11-28 21:01 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
2012-11-28 20:56 . 2012-11-28 21:02 -------- d-----w- c:\programdata\Hi-Rez Studios
2012-11-28 14:21 . 2012-11-28 14:21 -------- d-----w- c:\program files\WhoCrashed
2012-11-27 15:23 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6CA17EA6-6115-47CD-9B45-34D987F8FC20}\mpengine.dll
2012-11-27 14:37 . 2012-11-27 14:37 -------- d-----w- c:\users\Petr\AppData\Local\NBGI
2012-11-26 20:27 . 2012-11-26 20:27 -------- d-----w- c:\program files (x86)\Microsoft XNA
2012-11-26 15:35 . 2012-11-26 15:35 -------- d-----w- c:\users\Petr\AppData\Roaming\GRETECH
2012-11-26 15:34 . 2012-11-26 15:34 -------- d-----w- c:\program files (x86)\GRETECH
2012-11-26 14:12 . 2012-11-26 14:12 -------- d-----w- c:\users\Petr\AppData\Roaming\Apple Computer
2012-11-25 21:17 . 2012-11-25 21:17 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-11-25 12:41 . 2012-11-25 12:41 -------- d-----w- c:\windows\SysWow64\xlive
2012-11-25 12:40 . 2012-11-25 12:41 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-11-25 10:58 . 2012-11-25 10:58 -------- d-----w- c:\users\Petr\AppData\Local\SCE
2012-11-25 10:58 . 2012-11-25 10:58 -------- d-----w- C:\Crash
2012-11-25 10:58 . 2012-11-25 10:58 -------- d-----w- c:\users\Petr\AppData\Local\Sony Online Entertainment
2012-11-24 12:13 . 2012-11-24 12:13 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-11-22 17:16 . 2012-11-22 17:16 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-11-21 14:31 . 2012-11-21 14:31 -------- d-----w- c:\users\Petr\AppData\Local\PAYDAY
2012-11-19 21:28 . 2012-11-19 21:28 -------- d-----w- c:\users\Petr\AppData\Roaming\ToMMTi-Systems
2012-11-18 09:17 . 2012-11-18 09:17 -------- d-----w- c:\users\Petr\AppData\Local\FLT
2012-11-18 09:16 . 2010-06-02 03:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2012-11-18 09:16 . 2010-06-02 03:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2012-11-18 09:16 . 2010-06-02 03:55 239960 ----a-w- c:\windows\SysWow64\xactengine3_7.dll
2012-11-18 09:16 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\SysWow64\d3dcsx_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-11-17 22:42 . 2012-11-17 22:42 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2012-11-17 22:42 . 2012-11-17 22:42 -------- d-----w- c:\users\Petr\AppData\Roaming\SystemRequirementsLab
2012-11-17 18:39 . 2012-11-26 17:57 -------- d-----w- c:\programdata\Tunngle
2012-11-17 18:39 . 2012-11-17 21:47 -------- d-----w- c:\users\Petr\AppData\Roaming\Tunngle
2012-11-17 18:39 . 2009-09-16 06:02 31232 ----a-w- c:\windows\system32\drivers\tap0901t.sys
2012-11-17 18:39 . 2012-11-17 18:40 -------- d-----w- c:\program files (x86)\Tunngle
2012-11-15 14:58 . 2012-11-16 08:53 -------- d-----w- c:\users\Petr\AppData\Roaming\wargaming.net
2012-11-15 12:01 . 2012-11-15 12:01 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-11-15 12:01 . 2012-11-15 12:02 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-11-15 12:01 . 2012-11-28 16:53 -------- d-----w- c:\users\Petr\AppData\Roaming\DAEMON Tools Pro
2012-11-15 12:01 . 2012-11-15 12:01 -------- d-----w- c:\programdata\DAEMON Tools Pro
2012-11-15 11:52 . 2012-11-15 11:55 -------- d-----w- c:\users\Petr\AppData\Roaming\Registry Mechanic
2012-11-15 09:42 . 2012-11-15 19:00 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2012-11-15 09:41 . 2012-11-15 09:41 -------- d-----w- c:\users\Petr\AppData\Roaming\Product_RM
2012-11-15 09:41 . 2012-11-15 09:41 -------- d-----w- c:\programdata\PC Tools
2012-11-14 17:44 . 2012-11-14 17:44 -------- d-----w- c:\programdata\Uniblue
2012-11-14 17:39 . 2012-11-14 17:40 -------- d-----w- c:\program files\Core Temp
2012-11-14 14:33 . 2012-11-14 14:35 -------- d-----w- c:\program files (x86)\CPU-M Benchmark
2012-11-14 13:28 . 2012-11-14 13:28 -------- d-----w- c:\programdata\ATI
2012-11-14 13:28 . 2012-11-14 13:28 -------- d-----w- c:\program files (x86)\AMD AVT
2012-11-13 17:12 . 2012-11-14 14:32 -------- d-----w- c:\program files (x86)\Prime95
2012-11-13 14:04 . 2012-11-13 14:04 -------- d-----w- c:\program files (x86)\Common Files\Wrye Bash
2012-11-13 12:06 . 2012-11-13 12:07 -------- d-----w- C:\ENB & FXAA Remover
2012-11-13 08:18 . 2009-03-18 15:35 33856 ---ha-w- c:\windows\system32\hamachi.sys
2012-11-12 20:50 . 2012-11-12 20:50 11270656 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-11-12 20:36 . 2012-11-12 20:36 23436288 ----a-w- c:\windows\system32\atio6axx.dll
2012-11-12 20:27 . 2012-11-12 20:27 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-11-12 20:25 . 2012-11-12 20:25 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-11-12 20:25 . 2012-11-12 20:25 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-11-12 20:25 . 2012-11-12 20:25 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-11-12 20:25 . 2012-11-12 20:25 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-11-12 20:25 . 2012-11-12 20:25 16082944 ----a-w- c:\windows\system32\aticaldd64.dll
2012-11-12 20:21 . 2012-11-12 20:21 13703168 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-11-12 20:19 . 2012-11-12 20:19 18958336 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-11-12 20:16 . 2012-11-12 20:16 1137664 ----a-w- c:\windows\system32\aticfx64.dll
2012-11-12 20:04 . 2012-11-12 20:04 442368 ----a-w- c:\windows\system32\atidemgy.dll
2012-11-12 20:04 . 2012-11-12 20:04 548864 ----a-w- c:\windows\system32\atieclxx.exe
2012-11-12 20:03 . 2012-11-12 20:03 240640 ----a-w- c:\windows\system32\atiesrxx.exe
2012-11-12 20:02 . 2012-11-12 20:02 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-11-12 20:02 . 2012-11-12 20:02 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-11-12 20:02 . 2012-11-12 20:02 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-11-12 20:02 . 2012-11-12 20:02 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-11-12 20:00 . 2012-11-12 20:00 4674048 ----a-w- c:\windows\system32\atiumd6a.dll
2012-11-12 19:56 . 2012-11-12 19:56 7370752 ----a-w- c:\windows\system32\atidxx64.dll
2012-11-12 19:52 . 2012-11-12 19:52 6779392 ----a-w- c:\windows\system32\atiumd64.dll
2012-11-12 19:41 . 2012-11-12 19:41 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-11-12 19:37 . 2012-11-12 19:37 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-11-12 14:18 . 2012-11-12 14:18 -------- d-----w- c:\program files\Nexus Mod Manager1
2012-11-11 00:15 . 2012-11-11 00:15 -------- d-----w- c:\windows\PixArt
2012-11-11 00:15 . 2012-11-11 00:15 -------- d-----w- c:\program files (x86)\KYE
2012-11-11 00:15 . 2012-11-11 00:15 -------- d-----w- c:\program files (x86)\Common Files\PAC207
2012-11-11 00:15 . 2006-11-03 09:58 55296 ----a-w- c:\windows\SysWow64\Remove.exe
2012-11-11 00:10 . 2012-11-11 00:15 -------- d-----w- c:\windows\PAC207
2012-11-11 00:10 . 2012-11-11 00:10 -------- d-----w- c:\program files (x86)\ORITE
2012-11-11 00:10 . 2012-11-11 00:14 -------- d-----w- c:\windows\Downloaded Installations
2012-11-10 12:39 . 2012-11-10 12:39 -------- d-----w- c:\programdata\EA Core
2012-11-10 12:39 . 2012-11-10 12:39 -------- d-----w- c:\programdata\Electronic Arts
2012-11-10 11:59 . 2012-11-28 21:05 -------- d-----w- c:\users\Petr\AppData\Local\CrashDumps
2012-11-10 10:28 . 2012-10-12 18:09 25472 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-11-10 09:46 . 2012-11-10 09:49 -------- d-----w- c:\program files (x86)\Common Files\BioWare
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\users\Petr\AppData\Local\Zoner
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\users\Petr\AppData\Roaming\Zoner
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\programdata\Zoner
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\program files\Zoner
2012-11-09 22:58 . 2012-11-09 22:58 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-11-09 15:47 . 2012-11-09 15:47 -------- d-----w- c:\programdata\AVS4YOU
2012-11-08 21:27 . 2012-11-08 21:27 -------- d-----w- c:\program files (x86)\Common Files\Chameleon Manager
2012-11-08 13:08 . 2012-11-08 13:08 -------- d-----w- c:\users\Petr\AppData\Roaming\ATI
2012-11-07 17:46 . 2012-11-07 17:46 -------- d-----w- c:\users\Petr\AppData\Roaming\Publish Providers
2012-11-07 16:37 . 2012-11-07 16:37 -------- d-----w- c:\users\Petr\AppData\Roaming\The Creative Assembly
2012-11-07 16:19 . 2012-11-07 16:19 -------- d-----w- c:\users\Petr\AppData\Local\Macromedia
2012-11-07 16:18 . 2010-02-04 09:01 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_4.dll
2012-11-07 16:18 . 2010-02-04 09:01 528216 ----a-w- c:\windows\SysWow64\XAudio2_6.dll
2012-11-07 16:18 . 2010-02-04 09:01 238936 ----a-w- c:\windows\SysWow64\xactengine3_6.dll
2012-11-07 16:18 . 2010-02-04 09:01 22360 ----a-w- c:\windows\SysWow64\X3DAudio1_7.dll
2012-11-07 16:04 . 2012-11-07 16:04 -------- d-----w- c:\users\Petr\AppData\Roaming\Ghostbuster
2012-11-07 16:02 . 2012-11-07 16:02 -------- d-----w- c:\users\Petr\AppData\Local\Remove_Empty_Directories
2012-11-06 13:41 . 2007-04-04 17:53 81768 ----a-w- c:\windows\SysWow64\xinput1_3.dll
2012-11-05 21:09 . 2007-05-23 20:26 100352 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
2012-11-05 20:59 . 2012-11-05 20:59 -------- d-----w- c:\program files\HP
2012-11-05 20:54 . 2012-11-05 20:54 -------- d-----w- c:\programdata\HP
2012-11-05 17:42 . 2012-11-05 17:42 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-05 17:42 . 2012-11-05 17:42 -------- d-----w- c:\users\Petr\AppData\Local\PunkBuster
2012-11-04 21:09 . 2010-04-16 19:07 3610624 ----a-w- c:\windows\system32\avisynth.dll
2012-11-04 21:09 . 2009-04-29 19:25 2300928 ----a-w- c:\windows\system32\DevIL.dll
2012-11-04 21:07 . 2012-11-04 21:09 -------- d-----w- c:\program files (x86)\AviSynth 2.5
2012-11-04 13:02 . 2012-11-04 13:02 -------- d-----w- c:\users\Petr\AppData\Local\PassMark
2012-11-04 13:02 . 2012-11-04 13:02 -------- d-----w- c:\programdata\Passmark
2012-11-04 13:02 . 2012-11-04 13:02 -------- d-----w- c:\program files\PerformanceTest
2012-11-04 12:08 . 2012-11-04 12:08 294232 ----a-w- c:\windows\system32\drivers\VMM.sys
2012-11-04 11:59 . 2012-11-29 14:42 -------- d-----w- c:\program files (x86)\SpeedFan
2012-11-04 10:04 . 2012-11-04 10:13 -------- d-----w- c:\users\Petr\Heaven
2012-11-04 10:03 . 2012-11-04 10:03 -------- d-----w- c:\program files\Unigine
2012-11-04 09:56 . 2012-11-04 09:56 30592 ----a-w- c:\windows\system32\drivers\HWiNFO64A.SYS
2012-11-04 09:56 . 2012-11-04 09:56 -------- d-----w- c:\program files\HWiNFO64
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-12 20:52 . 2012-07-28 04:09 5624488 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-11-12 20:29 . 2012-10-23 03:21 70144 ----a-w- c:\windows\system32\coinst_9.01.8.dll
2012-11-12 20:18 . 2012-07-28 02:15 949248 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-11-12 20:14 . 2012-10-23 02:57 6678528 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-11-12 19:49 . 2012-07-28 01:32 3862528 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-11-12 19:41 . 2012-10-23 02:28 618496 ----a-w- c:\windows\system32\atiadlxx.dll
2012-11-12 19:41 . 2012-10-23 02:28 421888 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-11-12 19:38 . 2012-07-28 01:13 130048 ----a-w- c:\windows\system32\atiuxp64.dll
2012-11-12 19:38 . 2012-10-23 02:25 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-11-12 19:38 . 2012-10-23 02:25 104448 ----a-w- c:\windows\system32\atiu9p64.dll
2012-11-12 19:38 . 2012-07-28 01:13 83968 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-11-09 23:34 . 2012-11-09 23:34 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2012-10-29 15:53 . 2012-10-29 15:53 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-29 15:53 . 2012-10-29 15:53 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-26 19:32 . 2012-10-26 11:35 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-10-26 19:29 . 2012-10-20 12:29 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-10-25 11:49 . 2012-10-25 11:49 52736 ----a-w- c:\windows\ipuninst.exe
2012-10-24 18:00 . 2012-10-29 15:57 112640 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-10-22 21:45 . 2012-10-22 21:45 222720 ----a-w- c:\windows\system32\clinfo.exe
2012-10-22 21:45 . 2012-10-22 21:45 76288 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-10-22 21:45 . 2012-10-22 21:45 65536 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-10-22 21:45 . 2012-10-22 21:45 64512 ----a-w- c:\windows\system32\OVDecode64.dll
2012-10-22 21:44 . 2012-10-22 21:44 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-10-22 21:44 . 2012-10-22 21:44 34523136 ----a-w- c:\windows\system32\amdocl64.dll
2012-10-22 21:40 . 2012-10-22 21:40 28737536 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-10-22 21:36 . 2012-10-22 21:36 54784 ----a-w- c:\windows\system32\OpenCL.dll
2012-10-22 21:36 . 2012-10-22 21:36 50176 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-10-21 15:31 . 2012-10-21 15:31 314016 ----a-w- c:\windows\system32\drivers\atksgt.sys
2012-10-21 15:31 . 2012-10-21 15:31 43680 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2012-10-19 20:37 . 2012-10-19 20:38 151552 ----a-w- c:\windows\SysWow64\nvRegDev.dll
2012-10-19 20:37 . 2012-10-19 20:38 61440 ----a-w- c:\windows\SysWow64\nvPhotoshopUtil.dll
2012-10-19 20:37 . 2012-10-19 20:38 40960 ----a-w- c:\windows\SysWow64\nvISWOW64.dll
2012-10-16 08:38 . 2012-11-28 14:16 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 14:16 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 14:16 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-14 18:52 . 2012-10-14 18:52 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-10-14 18:52 . 2012-10-14 18:52 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-10-14 18:52 . 2012-10-14 18:52 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-10-14 18:45 . 2012-10-14 18:45 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-10-14 16:14 . 2012-10-14 16:14 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-14 16:14 . 2012-10-14 16:14 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-14 16:14 . 2012-10-14 16:14 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-14 16:14 . 2012-10-14 16:14 109144 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-10-11 03:08 . 2012-10-11 03:08 44928 ----a-w- c:\windows\system32\drivers\mcvidrv_x64.sys
2012-10-11 03:08 . 2012-10-11 03:08 29696 ----a-w- c:\windows\system32\drivers\mcaudrv_x64.sys
2012-10-04 15:29 . 2012-10-04 15:29 269176 ----a-w- c:\windows\system32\PDBoot.exe
2012-10-02 13:41 . 2012-10-02 13:41 256368 ----a-w- c:\windows\system32\oodbs.exe
2012-10-02 13:40 . 2012-10-02 13:40 10096 ----a-w- c:\windows\system32\oodbsrs.dll
2012-09-29 18:54 . 2012-10-29 14:20 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-14 19:19 . 2012-10-14 20:41 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-14 20:41 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-09-11 13:24 . 2012-09-11 13:24 126232 ----a-w- c:\windows\system32\drivers\DefragFs.sys
2012-09-06 16:05 . 2012-09-06 16:05 3953152 ----a-w- c:\windows\system32\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 2839552 ----a-w- c:\windows\SysWow64\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 198144 ----a-w- c:\windows\system32\SlotMaximizerAg.dll
2012-09-06 16:05 . 2012-09-06 16:05 161792 ----a-w- c:\windows\SysWow64\SlotMaximizerAg.dll
2012-09-05 08:12 . 2012-09-05 08:12 96768 ----a-w- c:\windows\system32\fsutil.exe
2012-09-05 08:12 . 2012-09-05 08:12 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS
2012-09-05 08:12 . 2012-09-05 08:12 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2012-09-05 08:12 . 2012-09-05 08:12 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2012-09-05 08:12 . 2012-09-05 08:12 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2012-09-05 08:12 . 2012-09-05 08:12 2565632 ----a-w- c:\windows\system32\esent.dll
2012-09-05 08:12 . 2012-09-05 08:12 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2012-09-05 08:12 . 2012-09-05 08:12 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2012-09-05 08:12 . 2012-09-05 08:12 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2012-09-05 08:12 . 2012-09-05 08:12 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2012-09-05 08:12 . 2012-09-05 08:12 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2012-09-05 08:11 . 2012-09-05 08:11 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-09-05 08:11 . 2012-09-05 08:11 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2012-09-05 08:11 . 2012-09-05 08:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2012-09-05 08:11 . 2012-09-05 08:11 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2012-09-05 08:11 . 2012-09-05 08:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2012-09-05 08:11 . 2012-09-05 08:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-09-05 08:11 . 2012-09-05 08:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2012-09-05 08:11 . 2012-09-05 08:11 503808 ----a-w- c:\windows\system32\srcore.dll
2012-09-05 08:11 . 2012-09-05 08:11 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2012-09-05 08:11 . 2012-09-05 08:11 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-09-05 08:11 . 2012-09-05 08:11 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-09-05 08:11 . 2012-09-05 08:11 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-09-05 08:11 . 2012-09-05 08:11 3216384 ----a-w- c:\windows\system32\msi.dll
2012-09-05 08:11 . 2012-09-05 08:11 2342400 ----a-w- c:\windows\SysWow64\msi.dll
2012-09-05 08:10 . 2012-09-05 08:10 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-09-05 08:10 . 2012-09-05 08:10 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-09-05 08:10 . 2012-09-05 08:10 751104 ----a-w- c:\windows\system32\win32spl.dll
2012-09-05 08:10 . 2012-09-05 08:10 67072 ----a-w- c:\windows\splwow64.exe
2012-09-05 08:10 . 2012-09-05 08:10 559104 ----a-w- c:\windows\system32\spoolsv.exe
2012-09-05 08:10 . 2012-09-05 08:10 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2012-09-05 08:10 . 2012-09-05 08:10 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-09-05 08:10 . 2012-09-05 08:10 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-09-05 08:10 . 2012-09-05 08:10 199680 ----a-w- c:\windows\system32\xmllite.dll
2012-09-05 08:10 . 2012-09-05 08:10 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe
2012-09-05 08:10 . 2012-09-05 08:10 778752 ----a-w- c:\windows\system32\mssvp.dll
2012-09-05 08:10 . 2012-09-05 08:10 75264 ----a-w- c:\windows\system32\msscntrs.dll
2012-09-05 08:10 . 2012-09-05 08:10 666624 ----a-w- c:\windows\SysWow64\mssvp.dll
2012-09-05 08:10 . 2012-09-05 08:10 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll
2012-09-05 08:10 . 2012-09-05 08:10 591872 ----a-w- c:\windows\system32\SearchIndexer.exe
2012-09-05 08:10 . 2012-09-05 08:10 491520 ----a-w- c:\windows\system32\mssph.dll
2012-09-05 08:10 . 2012-09-05 08:10 427520 ----a-w- c:\windows\SysWow64\SearchIndexer.exe
2012-09-05 08:10 . 2012-09-05 08:10 337408 ----a-w- c:\windows\SysWow64\mssph.dll
2012-09-05 08:10 . 2012-09-05 08:10 288256 ----a-w- c:\windows\system32\mssphtb.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-10-14 963984]
"WhatPulse"="c:\program files (x86)\WhatPulse\WhatPulse.exe" [2011-11-15 3990528]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-02-02 3034432]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-11-09 17877168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-12 642216]
.
c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Speedfan.lnk - c:\program files (x86)\SpeedFan\speedfan.exe [2012-9-12 4679672]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0OODBS
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-09 123856]
R3 2310_00;2310_00;c:\windows\system32\drivers\2310_00.sys [2009-06-12 170528]
R3 272x_1x;272x_1x;c:\windows\system32\drivers\272x_1x.sys [2012-04-24 612672]
R3 274x_3x;274x_3x;c:\windows\system32\drivers\274x_3x.sys [2012-04-24 240960]
R3 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2011-12-29 292136]
R3 ALSysIO;ALSysIO; [x]
R3 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys [2012-04-11 82560]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys [2010-12-07 19456]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys [2010-12-07 27648]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys [2010-12-07 27136]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys [2010-12-07 34304]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\lgandadb.sys [2010-08-02 31744]
R3 arcm_a64;arcm_a64;c:\windows\system32\drivers\arcm_a64.sys [2009-11-09 52768]
R3 asahci64;asahci64;c:\windows\system32\drivers\asahci64.sys [2012-01-06 49760]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-10-14 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-10-14 79360]
R3 DC133;DC133;c:\windows\system32\drivers\DC133.sys [2011-05-02 39320]
R3 DC150;DC150;c:\windows\system32\drivers\DC150.sys [2011-05-02 39832]
R3 DC154;DC154;c:\windows\system32\drivers\DC154.sys [2011-05-02 48136]
R3 DC300e;DC300e;c:\windows\system32\drivers\DC300e.sys [2011-05-02 40344]
R3 DC324e;DC324e;c:\windows\system32\drivers\DC324e.sys [2011-05-02 49752]
R3 DC4300;DC4300;c:\windows\system32\drivers\DC4300.sys [2011-05-02 48360]
R3 DC600e;DC600e;c:\windows\system32\drivers\DC600e.sys [2011-05-02 40744]
R3 DIRECTIO;DIRECTIO;c:\program files\PerformanceTest\DirectIo64.sys [2012-08-13 25704]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 hptiop;hptiop;c:\windows\system32\drivers\hptiop.sys [2009-05-25 17440]
R3 hptmv;hptmv;c:\windows\system32\drivers\hptmv.sys [2006-09-18 93472]
R3 hptmv6;hptmv6;c:\windows\system32\drivers\hptmv6.sys [2007-11-01 152096]
R3 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys [2012-06-20 578008]
R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys [2012-06-29 651224]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys [2012-10-11 44928]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys [2012-10-11 29696]
R3 megasas2;megasas2;c:\windows\system32\drivers\megasas2.sys [2012-02-28 51496]
R3 megasr1;megasr1;c:\windows\system32\drivers\MegaSR1.sys [2009-04-16 461320]
R3 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2011-05-06 182576]
R3 mv91cons;mv91cons;c:\windows\system32\drivers\mv91cons.sys [2012-02-23 27440]
R3 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2012-10-02 2552176]
R3 PAC207;VideoCAM GF112;c:\windows\system32\DRIVERS\PFC027.SYS [2006-12-05 572416]
R3 Pnp680;Pnp680;c:\windows\system32\drivers\pnp680.sys [2007-11-13 80424]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-11-09 19456]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-10-20 19952]
R3 rr172x;rr172x;c:\windows\system32\drivers\rr172x.sys [2007-11-01 124448]
R3 rr174x;rr174x;c:\windows\system32\drivers\rr174x.sys [2007-11-01 159264]
R3 rr2210;rr2210;c:\windows\system32\drivers\rr2210.sys [2007-11-01 153632]
R3 rr232x;rr232x;c:\windows\system32\drivers\rr232x.sys [2008-05-05 152096]
R3 rr2340;rr2340;c:\windows\system32\drivers\rr2340.sys [2009-12-31 162400]
R3 rr2522;rr2522;c:\windows\system32\drivers\rr2522.sys [2009-12-31 168032]
R3 rr276x;rr276x;c:\windows\system32\drivers\rr276x.sys [2012-04-24 241472]
R3 rr278x;rr278x;c:\windows\system32\drivers\rr278x.sys [2012-04-24 240960]
R3 rr62x;rr62x;c:\windows\system32\drivers\rr62x.sys [2010-06-16 156256]
R3 SI3112r;SI3112r;c:\windows\system32\drivers\SI3112r.sys [2007-02-01 164656]
R3 SI3114;SI3114;c:\windows\system32\drivers\SI3114.sys [2006-11-10 99120]
R3 SI3124;SI3124;c:\windows\system32\drivers\SI3124.sys [2006-11-02 113456]
R3 Si3124r5;Si3124r5;c:\windows\system32\drivers\Si3124r5.sys [2006-09-20 334640]
R3 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [2009-02-09 333864]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-10-23 2848168]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-11-09 29696]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-11-09 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-11-09 30208]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-11-14 744856]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 viamrx64;viamrx64;c:\windows\system32\drivers\viamrx64.sys [2010-12-02 161904]
R3 videX64;videX64;c:\windows\system32\drivers\videX64.sys [2010-02-11 15000]
R3 vmci;vmci;c:\windows\system32\drivers\vmci.sys [2012-01-17 116336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-15 1255736]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys [2012-04-11 42624]
S0 DC3410;DC3410;c:\windows\system32\drivers\DC3410.sys [2011-05-02 48328]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys [2012-06-29 26072]
S0 xfiltx64;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfiltx64.sys [2010-02-11 26776]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-15 283200]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2012-03-14 209768]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2012-03-14 148528]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO64A.SYS [2012-11-04 30592]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-12 240640]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2012-03-07 913144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2012-03-14 137144]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-19 2462128]
S2 PDFSFilter;PDFSFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys [2012-08-23 83224]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 XENfiltv;XENfiltv;c:\windows\system32\drivers\XENfiltv.sys [2009-07-31 25600]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-29 15:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 4081008]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ffjv34gb.default\
FF - ExtSQL: 2012-10-14 19:28; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ffjv34gb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2012-10-20 15:13; {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ffjv34gb.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF - ExtSQL: 2012-10-25 14:41; web2pdfextension@web2pdf.adobedotcom; c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
BHO-{3706EE7C-3CAD-445D-8A43-03EBC3B75908} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG16.00.00.01PROFESSIONAL"="4FD470B590D5C1DB7FF045490178A9AC981346E7AD1E79BB9A6398D52305B9344BC3F7AEC501FBADF19EE3458E2CD741AA7264E5EADCF266C13CDF591CF821A6A3A8773FAF8E0A98DC18FE348A3FE336A477FACFF6823FFB7CDF3764D22A63D5E10EE5A142C4B3E3892656F5F6C92F0AAE47B1C70611F84EF371D0014F26720A4D3820657461E4ED01480F3B5D523F4D373F154651FEDD429649428A1A72651E749A63EA3F93AD249232320DC757BBA5EA6E191713B64F55157488B1C005F6002B5F5467A201FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6171C11EC38DE3D8EDD5E5BE2F6E667BA7FD869164D6794622C1CF4F0B421515285D7A9F6318AD5E649DEA6304A176392F90F28E8799B192B8AC4FA1D4E91317D8CCD29D03790227FB3E4818C36548383254371DAD2D0D10614BA1FDAE55CF68B3B69E5E32D64A884927418B8BAAF92CAE7D892C7A9BF55AE3D47A57E242B510E7714C2AD429B45FEDF3805F9ABD2B88C74DB095D153EB7808B76873E07A4E1BABDFC540DF5514821ADA01E772C669214919E012F80AB837F991B70B55EF6C16E9D9565C421A4753D9E60E7BEBA9C314C15B2612F2CE6B74F154AC160CE54F9A73A1472FCEB3804CCEC6D1E3FA4281B476FF1C0B9ACD3443C405C1024D1738B094AF22E40533221EA6303AE4E0CBF48B8A0F7E80AE85D12B3F1EE2344B30C6859196FFCFE2ABDEC566222BB2368A0A67A3D24DBC31DEEF8461463776D16DC7704060D788B960A7BF45F8C9BDA840A95896F9B4C69D7F8C7AAA55EBEACEBA613178490ED1E124853CDE1C95AF5FEBEEA857446A0677EF0403B3848DC74FE300CC61C8560D26A2FF10D8625B5D94B866FB59D50750AC74E99F471CFE99CEC43A46868388327407A4702FBAC9F4CAE2F61804F2A1A02400FFBF98DE532DDA52C1377173D42FE8BE837210835BF7BC40670F3840792E4C7B38690D8BEB7D7EDBD04146D69B9A393BB188103D56F78FCDEC141C8DF95AC90BF4AA2B654AE0C5ECC15FEC0563BBDF73BB8E059E7BDB699126F3CBE718E36253C4FBD9CE27D61E3B25A21FD63CB5F29B1581D0B0CED8DB1FA855F9ABA9D435E378D9416EC43A1BF4F5983A231A67AEE6B2ABA2B2575BBAE7984C5A67F96F86DBEF37BBF374FFC07028E5744A7B765E0BE56E263D8FEDF51F163323FC80061D5EAE46D4DC92683A1B0E76D886FA0DDED80785F6F95E9FD2BCA8988D56316E97050B58984F101ACCC46C9BC2CF73802D78B22A12008C78023705451EF5EC862E68F3010BF424BD318AE8AE17CF2075534BD55BCD9A3DEB273519539270EBA82BBC693E5ED8F2635E95E741BDCD54A3F6DFA8C699320AA45ACE21013298B4361409A11978FF1E6747A47484AC6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
.
**************************************************************************
.
Celkový čas: 2012-11-29 15:44:13 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-29 14:44
ComboFix2.txt 2012-11-27 13:28
.
Před spuštěním: 196 538 703 872 bytes free
Po spuštění: 196 468 400 128 bytes free
.
- - End Of File - - 747124B78C38D7E3C23FC0DB97BB0140

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod jaro3 » 29 lis 2012 19:03

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

DirLook::
c:\windows\PAC207


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\windows\System32\autoconv.exe

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.

Stáhni si Memtest:

Do políčka vlož největší velikost Tvé jednotlivé paměti RAM (256,512 nebo 1024,2048) dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Clorky » 29 lis 2012 19:21

CFScript udělám až zítra, musím teď něco pracovat.
Ten soubor 0/43
CrystalDiskInfo mi nejde zapnout, ale posledně byl problémový ten 80GB, který používám jen pro nepotřebné soubory, jen čekám až dožije. Ten TB disk by měl být v pohodě. Dělám pravidelně defragmentace.
Memtest - RAMky mám nové 2 týdny, pokuď je to ale nutnost, pokusím se to nechat běžet zítra, možná se mi nějak povede rozjet i ten CrystalDisk.

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod memphisto » 29 lis 2012 20:15

Že to je nové neznamená, že to nebude pokažené...Klidně se může stát.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Clorky » 29 lis 2012 21:08

Udělám to tedy. A pokuď budou mít nějaké špatné výsledky, je to důvod k reklamaci?

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Clorky » 30 lis 2012 17:40

Combofix bude za chvíli, dám ho sem ale až večer, musím pryč.
Memtest (viz obrázek)
Ten Crystal se mi nechce spustit, ale o skutečnosti, jak je na tom ten 80GB vím, moc mu nezbývá.
Přílohy
Untitled.png

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Clorky » 30 lis 2012 18:40

ComboFix 12-11-30.02 - Petr 30.11.2012 18:23:38.5.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.8190.6796 [GMT 1:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Petr\AppData\Local\Temp\sfamcc00001.dll
c:\users\Petr\AppData\Local\Temp\sfareca00001.dll
.
Nakažená kopie c:\windows\System32\autoconv.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-convert_31bf3856ad364e35_6.1.7601.17514_none_fafb502abef1be40\autoconv.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-28 do 2012-11-30 )))))))))))))))))))))))))))))))
.
.
2012-11-30 17:26 . 2012-11-30 17:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-30 17:20 . 2012-11-30 17:20 -------- d-----w- c:\program files\CPUID
2012-11-30 13:29 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EA262BF9-551D-4E5A-BB33-7F06F33EB854}\mpengine.dll
2012-11-29 18:19 . 2012-11-29 18:27 -------- d-----w- c:\program files (x86)\CrystalDiskInfo
2012-11-28 21:02 . 2012-11-28 21:02 -------- d-----w- c:\users\Petr\AppData\Local\Chromium
2012-11-28 21:01 . 2012-11-28 21:01 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
2012-11-28 20:56 . 2012-11-28 21:02 -------- d-----w- c:\programdata\Hi-Rez Studios
2012-11-28 14:21 . 2012-11-29 17:37 -------- d-----w- c:\program files\WhoCrashed
2012-11-27 14:37 . 2012-11-27 14:37 -------- d-----w- c:\users\Petr\AppData\Local\NBGI
2012-11-26 20:27 . 2012-11-26 20:27 -------- d-----w- c:\program files (x86)\Microsoft XNA
2012-11-26 15:35 . 2012-11-26 15:35 -------- d-----w- c:\users\Petr\AppData\Roaming\GRETECH
2012-11-26 15:34 . 2012-11-26 15:34 -------- d-----w- c:\program files (x86)\GRETECH
2012-11-26 14:12 . 2012-11-26 14:12 -------- d-----w- c:\users\Petr\AppData\Roaming\Apple Computer
2012-11-25 21:17 . 2012-11-25 21:17 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-11-25 12:41 . 2012-11-25 12:41 -------- d-----w- c:\windows\SysWow64\xlive
2012-11-25 12:40 . 2012-11-25 12:41 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-11-25 10:58 . 2012-11-25 10:58 -------- d-----w- c:\users\Petr\AppData\Local\SCE
2012-11-25 10:58 . 2012-11-25 10:58 -------- d-----w- C:\Crash
2012-11-25 10:58 . 2012-11-25 10:58 -------- d-----w- c:\users\Petr\AppData\Local\Sony Online Entertainment
2012-11-24 12:13 . 2012-11-24 12:13 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-11-22 17:16 . 2012-11-22 17:16 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-11-21 14:31 . 2012-11-21 14:31 -------- d-----w- c:\users\Petr\AppData\Local\PAYDAY
2012-11-19 21:28 . 2012-11-19 21:28 -------- d-----w- c:\users\Petr\AppData\Roaming\ToMMTi-Systems
2012-11-18 09:17 . 2012-11-18 09:17 -------- d-----w- c:\users\Petr\AppData\Local\FLT
2012-11-18 09:16 . 2010-06-02 03:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2012-11-18 09:16 . 2010-06-02 03:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2012-11-18 09:16 . 2010-06-02 03:55 239960 ----a-w- c:\windows\SysWow64\xactengine3_7.dll
2012-11-18 09:16 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\SysWow64\d3dcsx_43.dll
2012-11-18 09:16 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-11-17 22:42 . 2012-11-17 22:42 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2012-11-17 22:42 . 2012-11-17 22:42 -------- d-----w- c:\users\Petr\AppData\Roaming\SystemRequirementsLab
2012-11-17 18:39 . 2012-11-26 17:57 -------- d-----w- c:\programdata\Tunngle
2012-11-17 18:39 . 2012-11-17 21:47 -------- d-----w- c:\users\Petr\AppData\Roaming\Tunngle
2012-11-17 18:39 . 2009-09-16 06:02 31232 ----a-w- c:\windows\system32\drivers\tap0901t.sys
2012-11-17 18:39 . 2012-11-17 18:40 -------- d-----w- c:\program files (x86)\Tunngle
2012-11-15 14:58 . 2012-11-16 08:53 -------- d-----w- c:\users\Petr\AppData\Roaming\wargaming.net
2012-11-15 12:01 . 2012-11-15 12:01 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-11-15 12:01 . 2012-11-15 12:02 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-11-15 12:01 . 2012-11-28 16:53 -------- d-----w- c:\users\Petr\AppData\Roaming\DAEMON Tools Pro
2012-11-15 12:01 . 2012-11-15 12:01 -------- d-----w- c:\programdata\DAEMON Tools Pro
2012-11-15 11:52 . 2012-11-15 11:55 -------- d-----w- c:\users\Petr\AppData\Roaming\Registry Mechanic
2012-11-15 09:42 . 2012-11-15 19:00 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2012-11-15 09:41 . 2012-11-15 09:41 -------- d-----w- c:\users\Petr\AppData\Roaming\Product_RM
2012-11-15 09:41 . 2012-11-15 09:41 -------- d-----w- c:\programdata\PC Tools
2012-11-14 17:44 . 2012-11-14 17:44 -------- d-----w- c:\programdata\Uniblue
2012-11-14 17:39 . 2012-11-14 17:40 -------- d-----w- c:\program files\Core Temp
2012-11-14 14:33 . 2012-11-14 14:35 -------- d-----w- c:\program files (x86)\CPU-M Benchmark
2012-11-14 13:28 . 2012-11-14 13:28 -------- d-----w- c:\programdata\ATI
2012-11-14 13:28 . 2012-11-14 13:28 -------- d-----w- c:\program files (x86)\AMD AVT
2012-11-13 17:12 . 2012-11-14 14:32 -------- d-----w- c:\program files (x86)\Prime95
2012-11-13 14:04 . 2012-11-13 14:04 -------- d-----w- c:\program files (x86)\Common Files\Wrye Bash
2012-11-13 12:06 . 2012-11-13 12:07 -------- d-----w- C:\ENB & FXAA Remover
2012-11-13 08:18 . 2009-03-18 15:35 33856 ---ha-w- c:\windows\system32\hamachi.sys
2012-11-12 20:50 . 2012-11-12 20:50 11270656 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-11-12 20:36 . 2012-11-12 20:36 23436288 ----a-w- c:\windows\system32\atio6axx.dll
2012-11-12 20:27 . 2012-11-12 20:27 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-11-12 20:25 . 2012-11-12 20:25 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-11-12 20:25 . 2012-11-12 20:25 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-11-12 20:25 . 2012-11-12 20:25 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-11-12 20:25 . 2012-11-12 20:25 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-11-12 20:25 . 2012-11-12 20:25 16082944 ----a-w- c:\windows\system32\aticaldd64.dll
2012-11-12 20:21 . 2012-11-12 20:21 13703168 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-11-12 20:19 . 2012-11-12 20:19 18958336 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-11-12 20:16 . 2012-11-12 20:16 1137664 ----a-w- c:\windows\system32\aticfx64.dll
2012-11-12 20:04 . 2012-11-12 20:04 442368 ----a-w- c:\windows\system32\atidemgy.dll
2012-11-12 20:04 . 2012-11-12 20:04 548864 ----a-w- c:\windows\system32\atieclxx.exe
2012-11-12 20:03 . 2012-11-12 20:03 240640 ----a-w- c:\windows\system32\atiesrxx.exe
2012-11-12 20:02 . 2012-11-12 20:02 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-11-12 20:02 . 2012-11-12 20:02 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-11-12 20:02 . 2012-11-12 20:02 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-11-12 20:02 . 2012-11-12 20:02 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-11-12 20:00 . 2012-11-12 20:00 4674048 ----a-w- c:\windows\system32\atiumd6a.dll
2012-11-12 19:56 . 2012-11-12 19:56 7370752 ----a-w- c:\windows\system32\atidxx64.dll
2012-11-12 19:52 . 2012-11-12 19:52 6779392 ----a-w- c:\windows\system32\atiumd64.dll
2012-11-12 19:41 . 2012-11-12 19:41 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-11-12 19:37 . 2012-11-12 19:37 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-11-12 14:18 . 2012-11-12 14:18 -------- d-----w- c:\program files\Nexus Mod Manager1
2012-11-11 00:15 . 2012-11-11 00:15 -------- d-----w- c:\windows\PixArt
2012-11-11 00:15 . 2012-11-11 00:15 -------- d-----w- c:\program files (x86)\KYE
2012-11-11 00:15 . 2012-11-11 00:15 -------- d-----w- c:\program files (x86)\Common Files\PAC207
2012-11-11 00:15 . 2006-11-03 09:58 55296 ----a-w- c:\windows\SysWow64\Remove.exe
2012-11-11 00:10 . 2012-11-11 00:15 -------- d-----w- c:\windows\PAC207
2012-11-11 00:10 . 2012-11-11 00:10 -------- d-----w- c:\program files (x86)\ORITE
2012-11-11 00:10 . 2012-11-11 00:14 -------- d-----w- c:\windows\Downloaded Installations
2012-11-10 12:39 . 2012-11-10 12:39 -------- d-----w- c:\programdata\EA Core
2012-11-10 12:39 . 2012-11-10 12:39 -------- d-----w- c:\programdata\Electronic Arts
2012-11-10 11:59 . 2012-11-28 21:05 -------- d-----w- c:\users\Petr\AppData\Local\CrashDumps
2012-11-10 10:28 . 2012-10-12 18:09 25472 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-11-10 09:46 . 2012-11-10 09:49 -------- d-----w- c:\program files (x86)\Common Files\BioWare
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\users\Petr\AppData\Local\Zoner
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\users\Petr\AppData\Roaming\Zoner
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\programdata\Zoner
2012-11-10 09:44 . 2012-11-10 09:44 -------- d-----w- c:\program files\Zoner
2012-11-09 22:58 . 2012-11-09 22:58 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-11-09 15:47 . 2012-11-09 15:47 -------- d-----w- c:\programdata\AVS4YOU
2012-11-08 21:27 . 2012-11-08 21:27 -------- d-----w- c:\program files (x86)\Common Files\Chameleon Manager
2012-11-08 13:08 . 2012-11-08 13:08 -------- d-----w- c:\users\Petr\AppData\Roaming\ATI
2012-11-07 17:46 . 2012-11-07 17:46 -------- d-----w- c:\users\Petr\AppData\Roaming\Publish Providers
2012-11-07 16:37 . 2012-11-07 16:37 -------- d-----w- c:\users\Petr\AppData\Roaming\The Creative Assembly
2012-11-07 16:19 . 2012-11-07 16:19 -------- d-----w- c:\users\Petr\AppData\Local\Macromedia
2012-11-07 16:18 . 2010-02-04 09:01 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_4.dll
2012-11-07 16:18 . 2010-02-04 09:01 528216 ----a-w- c:\windows\SysWow64\XAudio2_6.dll
2012-11-07 16:18 . 2010-02-04 09:01 238936 ----a-w- c:\windows\SysWow64\xactengine3_6.dll
2012-11-07 16:18 . 2010-02-04 09:01 22360 ----a-w- c:\windows\SysWow64\X3DAudio1_7.dll
2012-11-07 16:04 . 2012-11-07 16:04 -------- d-----w- c:\users\Petr\AppData\Roaming\Ghostbuster
2012-11-07 16:02 . 2012-11-07 16:02 -------- d-----w- c:\users\Petr\AppData\Local\Remove_Empty_Directories
2012-11-06 13:41 . 2007-04-04 17:53 81768 ----a-w- c:\windows\SysWow64\xinput1_3.dll
2012-11-05 21:09 . 2007-05-23 20:26 100352 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
2012-11-05 20:59 . 2012-11-05 20:59 -------- d-----w- c:\program files\HP
2012-11-05 20:54 . 2012-11-05 20:54 -------- d-----w- c:\programdata\HP
2012-11-05 17:42 . 2012-11-05 17:42 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-05 17:42 . 2012-11-05 17:42 -------- d-----w- c:\users\Petr\AppData\Local\PunkBuster
2012-11-04 21:09 . 2010-04-16 19:07 3610624 ----a-w- c:\windows\system32\avisynth.dll
2012-11-04 21:09 . 2009-04-29 19:25 2300928 ----a-w- c:\windows\system32\DevIL.dll
2012-11-04 21:07 . 2012-11-04 21:09 -------- d-----w- c:\program files (x86)\AviSynth 2.5
2012-11-04 13:02 . 2012-11-04 13:02 -------- d-----w- c:\users\Petr\AppData\Local\PassMark
2012-11-04 13:02 . 2012-11-04 13:02 -------- d-----w- c:\programdata\Passmark
2012-11-04 13:02 . 2012-11-04 13:02 -------- d-----w- c:\program files\PerformanceTest
2012-11-04 12:08 . 2012-11-04 12:08 294232 ----a-w- c:\windows\system32\drivers\VMM.sys
2012-11-04 11:59 . 2012-11-30 13:27 -------- d-----w- c:\program files (x86)\SpeedFan
2012-11-04 10:04 . 2012-11-04 10:13 -------- d-----w- c:\users\Petr\Heaven
2012-11-04 10:03 . 2012-11-04 10:03 -------- d-----w- c:\program files\Unigine
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-12 20:52 . 2012-07-28 04:09 5624488 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-11-12 20:29 . 2012-10-23 03:21 70144 ----a-w- c:\windows\system32\coinst_9.01.8.dll
2012-11-12 20:18 . 2012-07-28 02:15 949248 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-11-12 20:14 . 2012-10-23 02:57 6678528 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-11-12 19:49 . 2012-07-28 01:32 3862528 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-11-12 19:41 . 2012-10-23 02:28 618496 ----a-w- c:\windows\system32\atiadlxx.dll
2012-11-12 19:41 . 2012-10-23 02:28 421888 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-11-12 19:38 . 2012-07-28 01:13 130048 ----a-w- c:\windows\system32\atiuxp64.dll
2012-11-12 19:38 . 2012-10-23 02:25 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-11-12 19:38 . 2012-10-23 02:25 104448 ----a-w- c:\windows\system32\atiu9p64.dll
2012-11-12 19:38 . 2012-07-28 01:13 83968 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-11-09 23:34 . 2012-11-09 23:34 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2012-10-29 15:53 . 2012-10-29 15:53 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-29 15:53 . 2012-10-29 15:53 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-26 19:32 . 2012-10-26 11:35 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-10-26 19:29 . 2012-10-20 12:29 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-10-25 11:49 . 2012-10-25 11:49 52736 ----a-w- c:\windows\ipuninst.exe
2012-10-24 18:00 . 2012-10-29 15:57 112640 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-10-22 21:45 . 2012-10-22 21:45 222720 ----a-w- c:\windows\system32\clinfo.exe
2012-10-22 21:45 . 2012-10-22 21:45 76288 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-10-22 21:45 . 2012-10-22 21:45 65536 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-10-22 21:45 . 2012-10-22 21:45 64512 ----a-w- c:\windows\system32\OVDecode64.dll
2012-10-22 21:44 . 2012-10-22 21:44 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-10-22 21:44 . 2012-10-22 21:44 34523136 ----a-w- c:\windows\system32\amdocl64.dll
2012-10-22 21:40 . 2012-10-22 21:40 28737536 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-10-22 21:36 . 2012-10-22 21:36 54784 ----a-w- c:\windows\system32\OpenCL.dll
2012-10-22 21:36 . 2012-10-22 21:36 50176 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-10-21 15:31 . 2012-10-21 15:31 314016 ----a-w- c:\windows\system32\drivers\atksgt.sys
2012-10-21 15:31 . 2012-10-21 15:31 43680 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2012-10-19 20:37 . 2012-10-19 20:38 151552 ----a-w- c:\windows\SysWow64\nvRegDev.dll
2012-10-19 20:37 . 2012-10-19 20:38 61440 ----a-w- c:\windows\SysWow64\nvPhotoshopUtil.dll
2012-10-19 20:37 . 2012-10-19 20:38 40960 ----a-w- c:\windows\SysWow64\nvISWOW64.dll
2012-10-16 08:38 . 2012-11-28 14:16 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 14:16 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 14:16 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-14 18:52 . 2012-10-14 18:52 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-10-14 18:52 . 2012-10-14 18:52 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-10-14 18:52 . 2012-10-14 18:52 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-10-14 18:45 . 2012-10-14 18:45 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-10-14 16:14 . 2012-10-14 16:14 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-14 16:14 . 2012-10-14 16:14 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-14 16:14 . 2012-10-14 16:14 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-14 16:14 . 2012-10-14 16:14 109144 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-10-11 03:08 . 2012-10-11 03:08 44928 ----a-w- c:\windows\system32\drivers\mcvidrv_x64.sys
2012-10-11 03:08 . 2012-10-11 03:08 29696 ----a-w- c:\windows\system32\drivers\mcaudrv_x64.sys
2012-10-04 15:29 . 2012-10-04 15:29 269176 ----a-w- c:\windows\system32\PDBoot.exe
2012-10-02 13:41 . 2012-10-02 13:41 256368 ----a-w- c:\windows\system32\oodbs.exe
2012-10-02 13:40 . 2012-10-02 13:40 10096 ----a-w- c:\windows\system32\oodbsrs.dll
2012-09-29 18:54 . 2012-10-29 14:20 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-14 19:19 . 2012-10-14 20:41 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-14 20:41 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-09-11 13:24 . 2012-09-11 13:24 126232 ----a-w- c:\windows\system32\drivers\DefragFs.sys
2012-09-06 16:05 . 2012-09-06 16:05 3953152 ----a-w- c:\windows\system32\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 2839552 ----a-w- c:\windows\SysWow64\SlotMaximizerBe.dll
2012-09-06 16:05 . 2012-09-06 16:05 198144 ----a-w- c:\windows\system32\SlotMaximizerAg.dll
2012-09-06 16:05 . 2012-09-06 16:05 161792 ----a-w- c:\windows\SysWow64\SlotMaximizerAg.dll
2012-09-05 08:12 . 2012-09-05 08:12 96768 ----a-w- c:\windows\system32\fsutil.exe
2012-09-05 08:12 . 2012-09-05 08:12 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS
2012-09-05 08:12 . 2012-09-05 08:12 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2012-09-05 08:12 . 2012-09-05 08:12 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2012-09-05 08:12 . 2012-09-05 08:12 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2012-09-05 08:12 . 2012-09-05 08:12 2565632 ----a-w- c:\windows\system32\esent.dll
2012-09-05 08:12 . 2012-09-05 08:12 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2012-09-05 08:12 . 2012-09-05 08:12 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2012-09-05 08:12 . 2012-09-05 08:12 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2012-09-05 08:12 . 2012-09-05 08:12 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2012-09-05 08:12 . 2012-09-05 08:12 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2012-09-05 08:11 . 2012-09-05 08:11 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-09-05 08:11 . 2012-09-05 08:11 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2012-09-05 08:11 . 2012-09-05 08:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2012-09-05 08:11 . 2012-09-05 08:11 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2012-09-05 08:11 . 2012-09-05 08:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2012-09-05 08:11 . 2012-09-05 08:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-09-05 08:11 . 2012-09-05 08:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2012-09-05 08:11 . 2012-09-05 08:11 503808 ----a-w- c:\windows\system32\srcore.dll
2012-09-05 08:11 . 2012-09-05 08:11 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2012-09-05 08:11 . 2012-09-05 08:11 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-09-05 08:11 . 2012-09-05 08:11 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-09-05 08:11 . 2012-09-05 08:11 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-09-05 08:11 . 2012-09-05 08:11 3216384 ----a-w- c:\windows\system32\msi.dll
2012-09-05 08:11 . 2012-09-05 08:11 2342400 ----a-w- c:\windows\SysWow64\msi.dll
2012-09-05 08:10 . 2012-09-05 08:10 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-09-05 08:10 . 2012-09-05 08:10 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-09-05 08:10 . 2012-09-05 08:10 751104 ----a-w- c:\windows\system32\win32spl.dll
2012-09-05 08:10 . 2012-09-05 08:10 67072 ----a-w- c:\windows\splwow64.exe
2012-09-05 08:10 . 2012-09-05 08:10 559104 ----a-w- c:\windows\system32\spoolsv.exe
2012-09-05 08:10 . 2012-09-05 08:10 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2012-09-05 08:10 . 2012-09-05 08:10 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-09-05 08:10 . 2012-09-05 08:10 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-09-05 08:10 . 2012-09-05 08:10 199680 ----a-w- c:\windows\system32\xmllite.dll
2012-09-05 08:10 . 2012-09-05 08:10 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe
2012-09-05 08:10 . 2012-09-05 08:10 778752 ----a-w- c:\windows\system32\mssvp.dll
2012-09-05 08:10 . 2012-09-05 08:10 75264 ----a-w- c:\windows\system32\msscntrs.dll
2012-09-05 08:10 . 2012-09-05 08:10 666624 ----a-w- c:\windows\SysWow64\mssvp.dll
2012-09-05 08:10 . 2012-09-05 08:10 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll
2012-09-05 08:10 . 2012-09-05 08:10 591872 ----a-w- c:\windows\system32\SearchIndexer.exe
2012-09-05 08:10 . 2012-09-05 08:10 491520 ----a-w- c:\windows\system32\mssph.dll
2012-09-05 08:10 . 2012-09-05 08:10 427520 ----a-w- c:\windows\SysWow64\SearchIndexer.exe
2012-09-05 08:10 . 2012-09-05 08:10 337408 ----a-w- c:\windows\SysWow64\mssph.dll
2012-09-05 08:10 . 2012-09-05 08:10 288256 ----a-w- c:\windows\system32\mssphtb.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\PAC207 ----
.
2001-11-05 15:50 . 2001-11-05 15:50 69632 ----a-w- c:\windows\PAC207\AMCap.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-10-14 963984]
"WhatPulse"="c:\program files (x86)\WhatPulse\WhatPulse.exe" [2011-11-15 3990528]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-02-02 3034432]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-11-09 17877168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-12 642216]
.
c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Speedfan.lnk - c:\program files (x86)\SpeedFan\speedfan.exe [2012-9-12 4679672]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0OODBS
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-09 123856]
R3 2310_00;2310_00;c:\windows\system32\drivers\2310_00.sys [2009-06-12 170528]
R3 272x_1x;272x_1x;c:\windows\system32\drivers\272x_1x.sys [2012-04-24 612672]
R3 274x_3x;274x_3x;c:\windows\system32\drivers\274x_3x.sys [2012-04-24 240960]
R3 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2011-12-29 292136]
R3 ALSysIO;ALSysIO; [x]
R3 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys [2012-04-11 82560]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys [2010-12-07 19456]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys [2010-12-07 27648]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys [2010-12-07 27136]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys [2010-12-07 34304]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\lgandadb.sys [2010-08-02 31744]
R3 arcm_a64;arcm_a64;c:\windows\system32\drivers\arcm_a64.sys [2009-11-09 52768]
R3 asahci64;asahci64;c:\windows\system32\drivers\asahci64.sys [2012-01-06 49760]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-10-14 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-10-14 79360]
R3 DC133;DC133;c:\windows\system32\drivers\DC133.sys [2011-05-02 39320]
R3 DC150;DC150;c:\windows\system32\drivers\DC150.sys [2011-05-02 39832]
R3 DC154;DC154;c:\windows\system32\drivers\DC154.sys [2011-05-02 48136]
R3 DC300e;DC300e;c:\windows\system32\drivers\DC300e.sys [2011-05-02 40344]
R3 DC324e;DC324e;c:\windows\system32\drivers\DC324e.sys [2011-05-02 49752]
R3 DC4300;DC4300;c:\windows\system32\drivers\DC4300.sys [2011-05-02 48360]
R3 DC600e;DC600e;c:\windows\system32\drivers\DC600e.sys [2011-05-02 40744]
R3 DIRECTIO;DIRECTIO;c:\program files\PerformanceTest\DirectIo64.sys [2012-08-13 25704]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 hptiop;hptiop;c:\windows\system32\drivers\hptiop.sys [2009-05-25 17440]
R3 hptmv;hptmv;c:\windows\system32\drivers\hptmv.sys [2006-09-18 93472]
R3 hptmv6;hptmv6;c:\windows\system32\drivers\hptmv6.sys [2007-11-01 152096]
R3 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys [2012-06-20 578008]
R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys [2012-06-29 651224]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys [2012-10-11 44928]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys [2012-10-11 29696]
R3 megasas2;megasas2;c:\windows\system32\drivers\megasas2.sys [2012-02-28 51496]
R3 megasr1;megasr1;c:\windows\system32\drivers\MegaSR1.sys [2009-04-16 461320]
R3 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2011-05-06 182576]
R3 mv91cons;mv91cons;c:\windows\system32\drivers\mv91cons.sys [2012-02-23 27440]
R3 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2012-10-02 2552176]
R3 PAC207;VideoCAM GF112;c:\windows\system32\DRIVERS\PFC027.SYS [2006-12-05 572416]
R3 Pnp680;Pnp680;c:\windows\system32\drivers\pnp680.sys [2007-11-13 80424]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-11-09 19456]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-10-20 19952]
R3 rr172x;rr172x;c:\windows\system32\drivers\rr172x.sys [2007-11-01 124448]
R3 rr174x;rr174x;c:\windows\system32\drivers\rr174x.sys [2007-11-01 159264]
R3 rr2210;rr2210;c:\windows\system32\drivers\rr2210.sys [2007-11-01 153632]
R3 rr232x;rr232x;c:\windows\system32\drivers\rr232x.sys [2008-05-05 152096]
R3 rr2340;rr2340;c:\windows\system32\drivers\rr2340.sys [2009-12-31 162400]
R3 rr2522;rr2522;c:\windows\system32\drivers\rr2522.sys [2009-12-31 168032]
R3 rr276x;rr276x;c:\windows\system32\drivers\rr276x.sys [2012-04-24 241472]
R3 rr278x;rr278x;c:\windows\system32\drivers\rr278x.sys [2012-04-24 240960]
R3 rr62x;rr62x;c:\windows\system32\drivers\rr62x.sys [2010-06-16 156256]
R3 SI3112r;SI3112r;c:\windows\system32\drivers\SI3112r.sys [2007-02-01 164656]
R3 SI3114;SI3114;c:\windows\system32\drivers\SI3114.sys [2006-11-10 99120]
R3 SI3124;SI3124;c:\windows\system32\drivers\SI3124.sys [2006-11-02 113456]
R3 Si3124r5;Si3124r5;c:\windows\system32\drivers\Si3124r5.sys [2006-09-20 334640]
R3 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [2009-02-09 333864]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-10-23 2848168]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-11-09 29696]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-11-09 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-11-09 30208]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-11-14 744856]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 viamrx64;viamrx64;c:\windows\system32\drivers\viamrx64.sys [2010-12-02 161904]
R3 videX64;videX64;c:\windows\system32\drivers\videX64.sys [2010-02-11 15000]
R3 vmci;vmci;c:\windows\system32\drivers\vmci.sys [2012-01-17 116336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-15 1255736]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys [2012-04-11 42624]
S0 DC3410;DC3410;c:\windows\system32\drivers\DC3410.sys [2011-05-02 48328]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys [2012-06-29 26072]
S0 xfiltx64;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfiltx64.sys [2010-02-11 26776]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-15 283200]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2012-03-14 209768]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2012-03-14 148528]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO64A.SYS [2012-11-04 30592]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-12 240640]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2012-03-07 913144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2012-03-14 137144]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-19 2462128]
S2 PDFSFilter;PDFSFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys [2012-08-23 83224]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 XENfiltv;XENfiltv;c:\windows\system32\drivers\XENfiltv.sys [2009-07-31 25600]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-29 15:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 4081008]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ffjv34gb.default\
FF - ExtSQL: 2012-10-14 19:28; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ffjv34gb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2012-10-20 15:13; {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ffjv34gb.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF - ExtSQL: 2012-10-25 14:41; web2pdfextension@web2pdf.adobedotcom; c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
BHO-{3706EE7C-3CAD-445D-8A43-03EBC3B75908} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG16.00.00.01PROFESSIONAL"="4FD470B590D5C1DB7FF045490178A9AC981346E7AD1E79BB9A6398D52305B9344BC3F7AEC501FBADF19EE3458E2CD741AA7264E5EADCF266C13CDF591CF821A6A3A8773FAF8E0A98DC18FE348A3FE336A477FACFF6823FFB7CDF3764D22A63D5E10EE5A142C4B3E3892656F5F6C92F0AAE47B1C70611F84EF371D0014F26720A4D3820657461E4ED01480F3B5D523F4D373F154651FEDD429649428A1A72651E749A63EA3F93AD249232320DC757BBA5EA6E191713B64F55157488B1C005F6002B5F5467A201FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6171C11EC38DE3D8EDD5E5BE2F6E667BA7FD869164D6794622C1CF4F0B421515285D7A9F6318AD5E649DEA6304A176392F90F28E8799B192B8AC4FA1D4E91317D8CCD29D03790227FB3E4818C36548383254371DAD2D0D10614BA1FDAE55CF68B3B69E5E32D64A884927418B8BAAF92CAE7D892C7A9BF55AE3D47A57E242B510E7714C2AD429B45FEDF3805F9ABD2B88C74DB095D153EB7808B76873E07A4E1BABDFC540DF5514821ADA01E772C669214919E012F80AB837F991B70B55EF6C16E9D9565C421A4753D9E60E7BEBA9C314C15B2612F2CE6B74F154AC160CE54F9A73A1472FCEB3804CCEC6D1E3FA4281B476FF1C0B9ACD3443C405C1024D1738B094AF22E40533221EA6303AE4E0CBF48B8A0F7E80AE85D12B3F1EE2344B30C6859196FFCFE2ABDEC566222BB2368A0A67A3D24DBC31DEEF8461463776D16DC7704060D788B960A7BF45F8C9BDA840A95896F9B4C69D7F8C7AAA55EBEACEBA613178490ED1E124853CDE1C95AF5FEBEEA857446A0677EF0403B3848DC74FE300CC61C8560D26A2FF10D8625B5D94B866FB59D50750AC74E99F471CFE99CEC43A46868388327407A4702FBAC9F4CAE2F61804F2A1A02400FFBF98DE532DDA52C1377173D42FE8BE837210835BF7BC40670F3840792E4C7B38690D8BEB7D7EDBD04146D69B9A393BB188103D56F78FCDEC141C8DF95AC90BF4AA2B654AE0C5ECC15FEC0563BBDF73BB8E059E7BDB699126F3CBE718E36253C4FBD9CE27D61E3B25A21FD63CB5F29B1581D0B0CED8DB1FA855F9ABA9D435E378D9416EC43A1BF4F5983A231A67AEE6B2ABA2B2575BBAE7984C5A67F96F86DBEF37BBF374FFC07028E5744A7B765E0BE56E263D8FEDF51F163323FC80061D5EAE46D4DC92683A1B0E76D886FA0DDED80785F6F95E9FD2BCA8988D56316E97050B58984F101ACCC46C9BC2CF73802D78B22A12008C78023705451EF5EC862E68F3010BF424BD318AE8AE17CF2075534BD55BCD9A3DEB273519539270EBA82BBC693E5ED8F2635E95E741BDCD54A3F6DFA8C699320AA45ACE21013298B4361409A11978FF1E6747A47484AC6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
.
**************************************************************************
.
Celkový čas: 2012-11-30 18:38:05 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-30 17:38
ComboFix2.txt 2012-11-29 14:44
ComboFix3.txt 2012-11-27 13:28
.
Před spuštěním: 196 408 954 880 bytes free
Po spuštění: 196 324 282 368 bytes free
.
- - End Of File - - 4BBEA1D20F1579D81AE35C2EB286BD8C

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod jaro3 » 01 pro 2012 09:35

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vyčisti systém CCleanerem

Stáhni si OTC

na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.

Stáhni si HD Tune

-nainstaluj, spusť program, klikni na záložku Error scan
Spusť Start a počkej , až skončí svojí práci. Pokud budou všechny čtverečky zelené je disk OK , pokud budou některá červená , disk odchází.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Clorky » 01 pro 2012 16:19

Untitled.png
Vše hotovo
Příjde mi zvláštní, že je ten 80GB co se týče tohohle v pohodě...

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Žbeky » 01 pro 2012 19:04

Každopádně to vypadá, že tam žádný asiat schovaný není
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Je možné, aby se mi nějaký číňan hrabal v PC? +log

Příspěvekod Clorky » 01 pro 2012 19:21

Asi to byla jen shoda náhod, ale dost mě vyděsil možný keylogger...

Dá se podniknout ještě něco? Jestli je to vše, moc děkuji a dám fajfku.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 103 hostů