Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.orgVerze: v2013.01.25.06
Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
Pavel :: PAVEL-PC [administrátor]
25.1.2013 18:48:33
mbam-log-2013-01-25 (18-48-33).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 193684
Uplynulý čas: 3 minut, 52 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
# AdwCleaner v2.108 - Logfile created 01/25/2013 at 18:44:58
# Updated 24/01/2013 by Xplode
# Operating system : Windows 7 Ultimate (32 bits)
# User : Pavel - PAVEL-PC
# Boot Mode : Normal
# Running from : C:\Users\Pavel\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
Stopped & Deleted : IBUpdaterService
***** [Files / Folders] *****
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\file scout
Folder Deleted : C:\ProgramData\IBUpdaterService
Folder Deleted : C:\Users\Pavel\AppData\Local\Conduit
Folder Deleted : C:\Users\Pavel\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\on87fu3y.default\extensions\crossriderapp2258@crossrider.com
Folder Deleted : C:\Users\Pavel\AppData\Roaming\PerformerSoft
***** [Registry] *****
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.FBApi
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.FBApi.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055225558}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066226658}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440044224458}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65BCD620-07DD-012F-819F-073CF1B8F7C6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16457
[OK] Registry is clean.
-\\ Mozilla Firefox v17.0.1 (cs)
File : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\on87fu3y.default\prefs.js
Deleted : user_pref("extensions.crossriderapp2258.2258.InstallationTime", 1357153452);
Deleted : user_pref("extensions.crossriderapp2258.2258.active", true);
Deleted : user_pref("extensions.crossriderapp2258.2258.addressbar", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.addressbarenhanced", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.affid", "0");
Deleted : user_pref("extensions.crossriderapp2258.2258.backgroundjs", "\n\n//\n");
Deleted : user_pref("extensions.crossriderapp2258.2258.backgroundver", 19);
Deleted : user_pref("extensions.crossriderapp2258.2258.can_run_bg_code", true);
Deleted : user_pref("extensions.crossriderapp2258.2258.certdomaininstaller", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.changeprevious", false);
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.InstallationTime.value", "1357153452");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 [...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_aoi.value", "1357153452");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_blocklist.expiration", "Tue Jan 22 2013 19:[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_blocklist.value", "%22nonexistantdomain.com[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_country_code.expiration", "Tue Jan 29 2013 [...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_country_code.value", "%22CZ%22");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 [...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_crr.value", "1358879664");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030 0[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_currenttime.value", "%221358875092%22");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 [...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_hotfix20111102645.value", "%221%22");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installer_params.value", "%7B%22source_id%2[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installtime.expiration", "Fri Feb 01 2030 0[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_installtime.value", "%221356061492%22");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_parent_zoneid.value", "%2214019%22");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_pc_20120828.value", "1357156286418");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_product_id.value", "%2221%22");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie._GPL_zoneid.value", "%22126719%22");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.dbtest.value", "1357156282637");
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.lastrequest.expiration", "Fri Feb 01 2030 00:00:[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.cookie.lastrequest.value", "%7B%22path%22%3A%22/%22%2C%[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.description", "I Want This!");
Deleted : user_pref("extensions.crossriderapp2258.2258.domain", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.emailsig", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.enablesearch", false);
Deleted : user_pref("extensions.crossriderapp2258.2258.exposesites", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.fbremoteurl", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.group", 0);
Deleted : user_pref("extensions.crossriderapp2258.2258.homepage", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.iframe", false);
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_appVer.value", "104");
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_lastVersion.expiration", "Fri Feb [...]
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_lastVersion.value", "0");
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_meta.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_nextCheck.expiration", "Wed Jan 23[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_nextCheck.value", "true");
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.internaldb.Resources_queue.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp2258.2258.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.manifesturl", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.name", "I Want This");
Deleted : user_pref("extensions.crossriderapp2258.2258.newtab", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.opensearch", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_1000014.ver", 12);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_1000015.code", "\"CH\"==appAPI.platform&[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_1000015.name", "GPL Background (BG)");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_1000015.ver", 7);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.code", "(function(a){a.selectedText=f[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.name", "CrossriderAppUtils");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_13.ver", 2);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_14.name", "CrossriderUtils");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_14.ver", 2);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_15.code", "(function(f){var u={};var e=M[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_15.name", "FacebookFFIE");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_15.ver", 1);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_16.code", "if((typeof isBackground===\"u[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_16.name", "FFAppAPIWrapper");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_16.ver", 4);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_17.code", "if(typeof window!==\"undefine[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_17.name", "jQuery");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_17.ver", 3);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_47.code", "(function(){appAPI.ready=func[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_47.name", "resources_background");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_47.ver", 1);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPT[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_64.name", "appApiMessage");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_64.ver", 1);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_72.code", "if(appAPI.__should_activate_v[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_72.name", "appApiValidation");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_72.ver", 1);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_78.code", "if(typeof jQuery!==\"undefine[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_78.name", "CrossriderInfo");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins.plugin_78.ver", 2);
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins_lists.plugins_0", "14,78,16,64,47,72,1000015");
Deleted : user_pref("extensions.crossriderapp2258.2258.plugins_lists.plugins_1", "17,14,78,13,16,15,64,72,1000[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...]
Deleted : user_pref("extensions.crossriderapp2258.2258.pluginsversion", 29);
Deleted : user_pref("extensions.crossriderapp2258.2258.premium", true);
Deleted : user_pref("extensions.crossriderapp2258.2258.publisher", "215 Apps");
Deleted : user_pref("extensions.crossriderapp2258.2258.searchstatus", 0);
Deleted : user_pref("extensions.crossriderapp2258.2258.setnewtab", false);
Deleted : user_pref("extensions.crossriderapp2258.2258.settingsurl", "");
Deleted : user_pref("extensions.crossriderapp2258.2258.thankyou", "hxxp://iw.antthis.com/thankyou.html");
Deleted : user_pref("extensions.crossriderapp2258.2258.updateinterval", 360);
Deleted : user_pref("extensions.crossriderapp2258.2258.ver", 104);
Deleted : user_pref("extensions.crossriderapp2258.adsOldValue", -1);
Deleted : user_pref("extensions.crossriderapp2258.apps", "2258");
Deleted : user_pref("extensions.crossriderapp2258.bic", "13bfca641afba01d0a68af860622f72f");
Deleted : user_pref("extensions.crossriderapp2258.cid", 2258);
Deleted : user_pref("extensions.crossriderapp2258.firstrun", false);
Deleted : user_pref("extensions.crossriderapp2258.hadappinstalled", true);
Deleted : user_pref("extensions.crossriderapp2258.installationdate", 1357153452);
Deleted : user_pref("extensions.crossriderapp2258.lastcheck", 22647994);
Deleted : user_pref("extensions.crossriderapp2258.lastcheckitem", 22647995);
Deleted : user_pref("extensions.crossriderapp2258.misc.lastBgWorkerTimer", "1357155432915");
Deleted : user_pref("extensions.crossriderapp2258.misc.lastDomWorkerTimer", "1357155432913");
Deleted : user_pref("extensions.crossriderapp2258.modetype", "production");
Deleted : user_pref("extensions.enabledAddons", "%7B9AA46F4F-4DC7-4c06-97AF-5035170634FE%7D:5.0.3,crossriderap[...]
-\\ Google Chrome v24.0.1312.56
File : C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v [Unable to get version]
File : C:\Users\Pavel\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [15608 octets] - [25/01/2013 16:57:56]
AdwCleaner[R2].txt - [15669 octets] - [25/01/2013 18:44:42]
AdwCleaner[S1].txt - [15392 octets] - [25/01/2013 18:44:58]
########## EOF - C:\AdwCleaner[S1].txt - [15453 octets] ##########
ComboFix 12-07-25.04 - Pavel 29.01.2013 19:19:25.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.1789.1251 [GMT 1:00]
Spuštěný z: c:\users\Pavel\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\roboot.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-28 do 2013-01-29 )))))))))))))))))))))))))))))))
.
.
2013-01-29 18:26 . 2013-01-29 18:28 -------- d-----w- c:\users\Pavel\AppData\Local\temp
2013-01-29 18:26 . 2013-01-29 18:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-29 14:15 . 2013-01-29 14:15 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59B15996-CF6D-4C8A-8AE4-7C91D0676B8C}\offreg.dll
2013-01-27 20:48 . 2013-01-27 20:48 -------- d-----w- c:\users\Pavel\AppData\Local\Adobe
2013-01-25 15:50 . 2013-01-25 15:50 -------- d-----w- c:\users\Pavel\AppData\Roaming\Malwarebytes
2013-01-25 15:50 . 2013-01-25 15:50 -------- d-----w- c:\programdata\Malwarebytes
2013-01-25 15:50 . 2013-01-25 15:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-25 15:50 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-25 15:49 . 2013-01-25 15:49 -------- d-----w- c:\users\Pavel\AppData\Local\Programs
2013-01-25 13:01 . 2013-01-25 13:01 388096 ----a-r- c:\users\Pavel\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-01-25 13:01 . 2013-01-25 13:01 -------- d-----w- c:\program files\Trend Micro
2013-01-22 10:31 . 2013-01-22 10:31 25200 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2013-01-22 10:31 . 2013-01-22 10:31 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-01-22 10:31 . 2013-01-22 10:31 12400 ----a-w- c:\windows\system32\drivers\ggflt.sys
2013-01-22 10:30 . 2013-01-24 16:29 -------- d-----w- c:\programdata\Sony Ericsson
2013-01-22 10:25 . 2013-01-22 10:25 -------- d-----w- c:\programdata\Sony
2013-01-22 10:25 . 2013-01-22 10:25 -------- d-----w- c:\program files\Sony
2013-01-21 19:29 . 2013-01-21 19:29 -------- d-----w- c:\users\Pavel\AppData\Roaming\StatusWinks
2013-01-18 19:23 . 2013-01-18 19:23 -------- d-----w- c:\users\Pavel\AppData\Roaming\TeamViewer
2013-01-18 19:22 . 2013-01-18 19:22 -------- d-----w- c:\users\Pavel\AppData\Local\Microsoft Games
2013-01-10 21:41 . 2011-09-21 07:00 7269712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59B15996-CF6D-4C8A-8AE4-7C91D0676B8C}\mpengine.dll
2013-01-07 10:57 . 2013-01-07 10:57 -------- d-----w- c:\program files\Common Files\Adobe
2013-01-04 15:26 . 2008-11-26 10:47 102400 ----a-w- c:\windows\system32\Unzip32N.dll
2013-01-04 15:26 . 2008-11-26 10:47 151552 ----a-w- c:\windows\system32\Zip32N.dll
2013-01-04 15:26 . 2013-01-04 16:42 -------- d-----w- c:\program files\Primy kanal
2013-01-04 09:36 . 2013-01-04 09:36 -------- d-----w- c:\windows\Sun
2013-01-04 09:34 . 2013-01-04 05:54 746984 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-04 09:33 . 2013-01-04 09:33 -------- d-----w- c:\programdata\McAfee
2013-01-02 19:04 . 2013-01-02 19:04 -------- d-----w- c:\users\Pavel\AppData\Local\Macromedia
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-26 14:53 . 2012-07-28 11:11 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-26 14:53 . 2011-10-13 19:37 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-04 05:54 . 2012-12-19 17:28 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-12-19 19:46 . 2012-12-19 19:46 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-12-19 19:46 . 2012-12-19 19:46 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-12-19 19:46 . 2012-12-19 19:46 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-12-19 19:46 . 2012-12-19 19:46 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-12-19 19:46 . 2012-12-19 19:46 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-12-19 19:46 . 2012-12-19 19:46 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-12-19 19:46 . 2012-12-19 19:46 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-12-19 19:46 . 2012-12-19 19:46 367104 ----a-w- c:\windows\system32\html.iec
2012-12-19 19:46 . 2012-12-19 19:46 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-12-19 19:46 . 2012-12-19 19:46 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-12-19 19:46 . 2012-12-19 19:46 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-19 19:46 . 2012-12-19 19:46 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-12-19 19:46 . 2012-12-19 19:46 161792 ----a-w- c:\windows\system32\msls31.dll
2012-12-19 19:46 . 2012-12-19 19:46 152064 ----a-w- c:\windows\system32\wextract.exe
2012-12-19 19:46 . 2012-12-19 19:46 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-12-19 19:46 . 2012-12-19 19:46 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-12-19 19:46 . 2012-12-19 19:46 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-19 19:46 . 2012-12-19 19:46 11776 ----a-w- c:\windows\system32\mshta.exe
2012-12-19 19:46 . 2012-12-19 19:46 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-12-19 19:46 . 2012-12-19 19:46 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-12-19 19:46 . 2012-12-19 19:46 101888 ----a-w- c:\windows\system32\admparse.dll
2012-12-19 19:46 . 2012-12-19 19:46 801792 ----a-w- c:\windows\system32\FntCache.dll
2012-12-19 19:46 . 2012-12-19 19:46 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-12-19 19:46 . 2012-12-19 19:46 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-12-19 19:46 . 2012-12-19 19:46 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2012-12-19 19:46 . 2012-12-19 19:46 3181568 ----a-w- c:\windows\system32\mf.dll
2012-12-19 19:46 . 2012-12-19 19:46 283648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2012-12-19 19:46 . 2012-12-19 19:46 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-12-19 19:46 . 2012-12-19 19:46 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-12-19 19:46 . 2012-12-19 19:46 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2012-12-19 19:46 . 2012-12-19 19:46 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2012-12-19 19:46 . 2012-12-19 19:46 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2012-12-19 19:46 . 2012-12-19 19:46 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2012-12-19 19:46 . 2012-12-19 19:46 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2012-12-19 19:46 . 2012-12-19 19:46 107520 ----a-w- c:\windows\system32\cdd.dll
2012-12-19 19:46 . 2012-12-19 19:46 1074176 ----a-w- c:\windows\system32\DWrite.dll
2012-12-19 19:46 . 2012-12-19 19:46 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2012-12-19 17:28 . 2012-12-19 17:28 93640 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-11-29 08:26 . 2013-01-02 19:03 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"Sony PC Companion"="c:\program files\Sony\Sony PC Companion\PCCompanion.exe" [2013-01-07 446648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
.
c:\users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 ALSysIO;ALSysIO;c:\users\Pavel\AppData\Local\Temp\ALSysIO.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\DRIVERS\s916bus.sys [x]
R3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s916mdfl.sys [x]
R3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s916mdm.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x]
S3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
S3 yukonw7;Ovladač NDIS6.2 Miniport pro řadič Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-01-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-28 14:53]
.
2013-01-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2855798801-2560433423-1982038742-1000Core.job
- c:\users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-12-02 14:13]
.
2013-01-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2855798801-2560433423-1982038742-1000UA.job
- c:\users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-12-02 14:13]
.
2013-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-14 14:34]
.
2013-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-14 14:34]
.
2013-01-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2855798801-2560433423-1982038742-1000Core.job
- c:\users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-30 22:13]
.
2013-01-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2855798801-2560433423-1982038742-1000UA.job
- c:\users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-30 22:13]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.google.cz/IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\on87fu3y.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-01-29 19:33:24
ComboFix-quarantined-files.txt 2013-01-29 18:33
.
Před spuštěním: Volných bajtů: 38 723 555 328
Po spuštění: Volných bajtů: 38 605 336 576
.
- - End Of File - - AE53E0F112ECBF07AF872E5AFC06C615