Vše podle návodu jsem udělal tady je ten log.
ComboFix 13-01-17.04 - Acer 19.01.2013 15:52:14.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3767.2530 [GMT 1:00]
Spuštěný z: c:\users\Acer\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Acer\Desktop\CFScript.txt.txt
AV: AVG Internet Security 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
SP: AVG Internet Security 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\aswBoot.exe"
"c:\windows\system32\drivers\EagleX64.sys"
"c:\windows\system32\GameMon.des"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2451203615-349451005-3616792112-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2451203615-349451005-3616792112-1001UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.123\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.123\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.123\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.123\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.123\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.21.123\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.123\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.123\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.123\psuser.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.125\GoogleUpdateB6998767.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\users\Acer\AppData\Local\Google\Update
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\GoogleUpdate.exe
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateBroker.exe
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateHelper.msi
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateOnDemand.exe
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateSetup.exe
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdate.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_am.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ar.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_bg.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_bn.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ca.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_cs.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_da.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_de.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_el.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_en-GB.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_en.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_es-419.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_es.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_et.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_fa.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_fi.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_fil.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_fr.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_gu.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_hi.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_hr.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_hu.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_id.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_is.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_it.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_iw.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ja.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_kn.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ko.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_lt.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_lv.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ml.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_mr.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ms.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_nl.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_no.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_pl.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_pt-BR.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_pt-PT.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ro.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ru.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_sk.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_sl.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_sr.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_sv.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_sw.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ta.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_te.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_th.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_tr.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_uk.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_ur.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_vi.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_zh-CN.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\goopdateres_zh-TW.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\psmachine.dll
c:\users\Acer\AppData\Local\Google\Update\1.3.21.123\psuser.dll
c:\users\Acer\AppData\Local\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.125\GoogleUpdateB6998767.exe
c:\users\Acer\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\24.0.1312.52\24.0.1312.52_23.0.1271.97_chrome_updater.exe
c:\users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
c:\users\Acer\AppData\Local\TempDIR
c:\users\Acer\AppData\Local\TempDIR\GFInstaller\AppName.txt
c:\users\Acer\AppData\Local\TempDIR\GFInstaller\DownloadURL.txt
c:\users\Acer\AppData\Local\TempDIR\GFInstaller\GFInstaller.exe
c:\users\Acer\AppData\Local\TempDIR\GFInstaller\Channel.txt
c:\windows\system32\aswBoot.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2451203615-349451005-3616792112-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2451203615-349451005-3616792112-1001UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_EAGLEX64
-------\Service_EagleX64
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-19 do 2013-01-19 )))))))))))))))))))))))))))))))
.
.
2013-01-19 15:03 . 2013-01-19 15:03 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-19 15:03 . 2013-01-19 15:03 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-01-19 15:03 . 2013-01-19 15:03 -------- d-----w- c:\users\hedev\AppData\Local\temp
2013-01-19 15:03 . 2013-01-19 15:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-19 14:11 . 2013-01-19 14:11 -------- d-----w- c:\users\Acer\AppData\Local\GFInstaller
2013-01-17 18:48 . 2013-01-17 18:48 -------- d-----w- c:\program files (x86)\GTA3Mods
2013-01-15 15:07 . 2013-01-18 14:41 -------- d-----w- c:\users\Acer\AppData\Local\dxhr
2013-01-15 15:06 . 2013-01-15 15:06 -------- d-----w- c:\users\Acer\AppData\Local\28050
2013-01-15 14:57 . 2013-01-15 15:02 -------- d-----w- c:\users\Acer\AppData\Local\Ubisoft Game Launcher
2013-01-15 14:56 . 2013-01-15 14:56 -------- d-----w- c:\users\Acer\AppData\Roaming\Ubisoft
2013-01-15 14:56 . 2013-01-15 14:56 -------- d-----w- c:\programdata\Ubisoft
2013-01-15 14:40 . 2013-01-15 14:40 -------- d-----w- c:\program files (x86)\Ubisoft
2013-01-15 11:52 . 2013-01-15 11:52 -------- d-----w- c:\programdata\Friday's games
2013-01-15 11:52 . 2013-01-15 11:52 -------- d-----w- c:\program files (x86)\Nadherna zahrada
2013-01-15 11:48 . 2013-01-15 11:48 -------- d-----w- c:\users\Acer\AppData\Roaming\PRIBEH~1
2013-01-15 11:48 . 2013-01-15 11:48 -------- d-----w- c:\users\Acer\AppData\Roaming\Pribeh vily - Vyprava za kvetinami
2013-01-15 11:31 . 2013-01-15 11:31 -------- d-----w- c:\users\Acer\AppData\Roaming\Meridian93
2013-01-15 11:31 . 2013-01-15 11:31 -------- d-----w- c:\program files (x86)\Pribeh vily - Vyprava za kvetinami
2013-01-13 16:21 . 2013-01-13 16:21 -------- d-----w- c:\program files (x86)\Ledova kralovna 2
2013-01-11 17:02 . 2013-01-11 17:02 -------- d-----w- c:\program files (x86)\Resource Hacker
2013-01-11 15:26 . 2013-01-11 16:59 -------- d-----w- c:\programdata\SystemExplorer
2013-01-11 15:26 . 2013-01-11 15:26 -------- d-----w- c:\program files (x86)\System Explorer
2013-01-10 15:52 . 2013-01-10 15:52 -------- d-----w- c:\users\Acer\AppData\Local\Programs
2013-01-10 15:40 . 2013-01-10 15:40 -------- d-----w- c:\users\Acer\AppData\Roaming\Specialbit
2013-01-10 15:39 . 2013-01-10 15:39 -------- d-----w- c:\program files (x86)\Zlodeji dusi
2013-01-09 15:46 . 2013-01-09 15:46 15739912 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-01-09 15:41 . 2012-11-22 05:44 800768 ----a-w- c:\windows\system32\usp10.dll
2013-01-09 15:40 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys
2013-01-07 19:37 . 2013-01-07 19:37 -------- d-----w- c:\users\Acer\AppData\Local\Gordonsys_2.0
2013-01-07 19:37 . 2013-01-07 19:37 -------- d-----w- c:\users\Acer\AppData\Roaming\Gordonsys 2.0
2013-01-05 15:49 . 2013-01-05 15:49 -------- d-----w- C:\AeriaGames
2013-01-05 15:07 . 2013-01-05 15:07 -------- d-----w- c:\users\Acer\AppData\Local\Chromium
2013-01-02 14:27 . 2013-01-02 14:27 -------- d-----w- c:\users\Acer\AppData\Roaming\picpick
2013-01-02 13:04 . 2013-01-04 18:23 -------- d-----w- c:\users\Acer\AppData\Roaming\FileZilla
2012-12-31 15:25 . 2012-12-31 15:25 -------- d-----w- c:\users\Acer\AppData\Local\CRE
2012-12-29 20:25 . 2013-01-10 16:08 -------- d-----w- c:\program files (x86)\ASCII Art Generator
2012-12-22 08:21 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-22 08:21 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-22 08:21 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-22 08:21 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-10 14:47 . 2012-05-25 21:23 67599240 ----a-w- c:\windows\system32\MRT.exe
2013-01-09 15:47 . 2012-11-13 15:59 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-09 15:47 . 2011-11-07 16:09 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-22 16:50 . 2012-12-18 16:43 183112 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-12-18 16:43 . 2012-12-18 16:43 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-12-14 15:49 . 2012-07-06 19:15 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-30 04:45 . 2013-01-09 15:41 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-11-15 22:33 . 2012-11-15 22:33 111968 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2012-11-14 07:06 . 2012-12-12 21:10 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-11-14 06:32 . 2012-12-12 21:10 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-11-14 06:11 . 2012-12-12 21:10 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 06:04 . 2012-12-12 21:10 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-11-14 06:04 . 2012-12-12 21:10 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 06:02 . 2012-12-12 21:10 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 06:02 . 2012-12-12 21:10 237056 ----a-w- c:\windows\system32\url.dll
2012-11-14 05:59 . 2012-12-12 21:10 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-11-14 05:58 . 2012-12-12 21:10 816640 ----a-w- c:\windows\system32\jscript.dll
2012-11-14 05:57 . 2012-12-12 21:10 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 05:57 . 2012-12-12 21:10 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 05:55 . 2012-12-12 21:10 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-11-14 05:55 . 2012-12-12 21:10 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-11-14 05:53 . 2012-12-12 21:10 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-11-14 05:52 . 2012-12-12 21:10 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-14 05:46 . 2012-12-12 21:10 248320 ----a-w- c:\windows\system32\ieui.dll
2012-11-14 02:09 . 2012-12-12 21:10 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-11-14 01:58 . 2012-12-12 21:10 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-11-14 01:57 . 2012-12-12 21:10 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-11-14 01:49 . 2012-12-12 21:10 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-11-14 01:48 . 2012-12-12 21:10 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-11-14 01:44 . 2012-12-12 21:10 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-11-09 05:45 . 2012-12-12 13:20 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-09 04:42 . 2012-12-12 13:20 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-11-08 17:24 . 2012-11-30 14:21 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{97874F42-6ED6-4BEC-9444-A7488C658A01}\mpengine.dll
2012-11-02 05:59 . 2012-12-12 13:19 478208 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 05:11 . 2012-12-12 13:19 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2012-10-22 12:02 . 2012-10-22 12:02 154464 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-04-26 3111744]
"Akamai NetSession Interface"="c:\users\Acer\AppData\Local\Akamai\netsession_win.exe" [2012-10-09 4441920]
"SystemExplorerAutoStart"="c:\program files (x86)\System Explorer\SystemExplorer.exe" [2012-12-02 2846168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2011-06-17 266496]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [x]
R3 ATP;Comodo Unite Miniport Driver;c:\windows\system32\DRIVERS\cmdatp.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-09-22 243712]
R3 SystemExplorerHelpService;System Explorer Service;c:\program files (x86)\System Explorer\service\SystemExplorerService64.exe [2012-11-25 821720]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-05 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-10-15 63328]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-11-15 111968]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-08-30 30056]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [2012-09-04 50296]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-10-22 154464]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-05-06 283200]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2011-11-07 22648]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2011-11-07 20520]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2011-11-07 62776]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2013\avgfws.exe [2012-12-10 1342024]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104]
S2 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2011-04-02 173424]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2011-01-05 867712]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2011-05-26 29696]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2012-08-02 158944]
S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2011-06-17 255744]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-07-16 2673064]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-13 135560]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 158976]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-06-21 287232]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2010-05-15 384040]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-01-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-13 15:47]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-02-08 00:49 23432 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-23 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-23 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-23 415256]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552]
"ETDWare"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-01-05 860040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://google.cz/uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: ????3??
IE: ????3??????
IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: ????3?? - c:\users\Acer\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Acer\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
AddRemove-Age of Empires - d:\age of empires 1\Uninstal.exe
AddRemove-Age of Empires 2.0 - d:\age of empires 2\UNINSTAL.EXE
AddRemove-Age of Empires Expansion 1.0 - d:\age of empires 1\UNINSTX.EXE
AddRemove-Age of Empires II: The Conquerors Expansion 1.0 - d:\age of empires 2\UNINSTALX.EXE
AddRemove-Call of Duty Modern Warfare 2_is1 - d:\mw2\Modern Warfare 2\unins000.exe
AddRemove-Company of Heroes - d:\company of heroes – kopie\Uninstall_English.exe
AddRemove-Postal III_is1 - d:\postal iii\Postal 3\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2451203615-349451005-3616792112-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@="c:\\Users\\Acer\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2451203615-349451005-3616792112-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@="c:\\Users\\Acer\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_USERS\S-1-5-21-2451203615-349451005-3616792112-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:c8,2a,70,ae,72,73,89,c8,e5,2a,bc,ba,a1,1e,2d,69,bc,7f,9d,59,82,6e,56,
a2,d7,b1,81,96,fa,77,b2,cc,f6,8a,f7,fe,1c,48,7a,1b,1d,35,8f,8c,91,a6,4a,ad,\
"??"=hex:ee,82,11,f1,57,02,9b,76,9e,eb,e5,c6,6a,97,f4,9d
.
[HKEY_USERS\S-1-5-21-2451203615-349451005-3616792112-1001\Software\SecuROM\License information*]
"datasecu"=hex:64,82,27,89,64,60,d8,14,8c,44,b0,8e,72,a5,25,05,12,4d,7f,18,dd,
c2,60,02,84,46,3f,98,7d,48,5b,72,1d,1a,e5,0f,d8,68,51,98,bf,15,ed,e0,8b,66,\
"rkeysecu"=hex:e8,89,da,b9,56,c3,e1,c8,03,72,f7,61,e6,fe,f1,d7
.
[HKEY_USERS\S-1-5-21-2451203615-349451005-3616792112-1001_Classes\Wow6432Node\CLSID\{5a02a6ef-9a63-47bc-a2bd-f6a695fbb87b}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000f4
"Therad"=dword:00000001
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_USERS\S-1-5-21-2451203615-349451005-3616792112-1001_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):ae,9d,ad,c3,2d,d6,fb,e1,67,11,8e,2a,be,8c,1e,ca,60,6f,6d,cd,cd,
ab,bf,de,23,99,c4,e7,35,0f,a0,5b,cc,93,23,57,34,1f,07,e1,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-01-19 16:19:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-19 15:19
ComboFix2.txt 2013-01-19 00:29
.
Před spuštěním: Volných bajtů: 105 414 815 744
Po spuštění: Volných bajtů: 104 592 199 680
.
- - End Of File - - 5D43554BBE817134A7BE1D62AD23A110