ComboFix 13-02-03.02 - Uzivatel 03.02.2013 17:33:54.4.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3326.2064 [GMT 1:00]
Spuštěný z: c:\users\Uzivatel\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Uzivatel\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\system32\drivers\EagleXNt.sys"
"c:\windows\system32\GameMon.des"
"c:\windows\Tasks\GlaryInitialize.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
c:\windows\system32\GameMon.des
c:\windows\Tasks\GlaryInitialize.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_EAGLEXNT
-------\Service_EagleXNt
-------\Service_npggsvc
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-03 do 2013-02-03 )))))))))))))))))))))))))))))))
.
.
2013-02-03 16:39 . 2013-02-03 16:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-03 10:02 . 2013-02-03 10:02 -------- d-----w- c:\users\Uzivatel\AppData\Local\AMD
2013-02-03 10:02 . 2013-02-03 10:02 -------- d-----w- c:\users\Uzivatel\AppData\Local\ATI
2013-02-03 09:52 . 2013-02-03 09:52 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{31C80E3C-8859-4ADB-97DE-DC34E63C488D}\offreg.dll
2013-02-02 22:14 . 2013-02-02 22:14 -------- d-----w- c:\programdata\Malwarebytes
2013-02-02 22:14 . 2013-02-02 22:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-02 22:14 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-02 22:14 . 2013-02-02 22:14 -------- d-----w- c:\users\Uzivatel\AppData\Local\Programs
2013-02-01 09:22 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{31C80E3C-8859-4ADB-97DE-DC34E63C488D}\mpengine.dll
2013-01-29 16:57 . 2013-01-29 17:02 -------- d-----w- c:\users\Uzivatel\AppData\Roaming\Wise Registry Cleaner
2013-01-29 16:56 . 2013-01-29 16:56 -------- d-----w- c:\program files\Wise
2013-01-27 10:22 . 2013-01-27 10:22 -------- d-----w- c:\program files\Common Files\Skype
2013-01-27 10:22 . 2013-02-03 16:38 -------- d-----r- c:\program files\Skype
2013-01-27 10:21 . 2013-01-27 10:21 -------- d-----w- c:\programdata\ATI
2013-01-27 10:21 . 2013-01-27 10:21 -------- d-----w- c:\program files\AMD AVT
2013-01-27 10:21 . 2013-01-27 10:21 -------- d-----w- c:\program files\AMD APP
2013-01-17 15:11 . 2013-01-17 15:11 -------- d-----w- c:\users\Uzivatel\AppData\Local\My Games
2013-01-16 14:44 . 2013-02-03 16:22 138032 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-01-16 14:36 . 2013-02-03 16:22 281688 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-01-16 14:36 . 2013-01-16 14:36 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-01-09 14:21 . 2013-01-29 14:42 -------- dc-h--w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}
2013-01-09 14:18 . 2013-01-09 14:18 -------- d-----w- c:\users\Uzivatel\AppData\Roaming\Merver
2013-01-09 14:18 . 2013-01-09 14:18 -------- d-----w- c:\users\Uzivatel\AppData\Local\PackageAware
2013-01-09 13:32 . 2012-11-30 04:47 293376 ----a-w- c:\windows\system32\KernelBase.dll
2013-01-06 11:34 . 2013-01-06 11:43 -------- d-----w- c:\users\Uzivatel\AppData\Roaming\SpieleEntwicklungsKombinat
2013-01-06 11:33 . 2013-01-26 21:36 -------- d-----w- c:\programdata\SpieleEntwicklungsKombinat
2013-01-06 11:32 . 2013-01-06 11:43 271360 ----a-w- c:\windows\system32\drivers\atksgt.sys
2013-01-06 11:32 . 2013-01-06 11:32 18048 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2013-01-05 17:08 . 2013-01-05 17:08 -------- d-----w- c:\users\Uzivatel\AppData\Local\GHISLER
2013-01-05 17:07 . 2013-01-05 17:07 -------- d-----w- C:\totalcmd
2013-01-05 16:41 . 2013-01-05 16:41 -------- d-----w- c:\program files\VS Revo Group
2013-01-05 13:33 . 2013-01-05 13:33 -------- d-----w- c:\users\Uzivatel\AppData\Local\WB Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-03 16:22 . 2012-01-04 16:16 281688 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-02-03 16:16 . 2011-05-31 17:29 281688 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-01-17 00:28 . 2011-05-30 08:56 232336 ------w- c:\windows\system32\MpSigStub.exe
2013-01-09 13:55 . 2012-04-07 08:32 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-09 13:55 . 2011-05-30 10:07 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-19 20:50 . 2011-01-13 02:30 5630200 ----a-w- c:\windows\system32\atiumdag.dll
2012-12-19 20:47 . 2012-12-19 20:47 9647104 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-12-19 20:22 . 2012-12-19 20:22 58880 ----a-w- c:\windows\system32\coinst_9.012.dll
2012-12-19 20:19 . 2012-12-19 20:19 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-12-19 20:18 . 2012-12-19 20:18 46080 ----a-w- c:\windows\system32\aticalrt.dll
2012-12-19 20:17 . 2012-12-19 20:17 44032 ----a-w- c:\windows\system32\aticalcl.dll
2012-12-19 20:13 . 2012-12-19 20:13 13703168 ----a-w- c:\windows\system32\aticaldd.dll
2012-12-19 20:12 . 2012-12-19 20:12 18982400 ----a-w- c:\windows\system32\atioglxx.dll
2012-12-19 20:09 . 2011-01-13 03:01 960512 ----a-w- c:\windows\system32\aticfx32.dll
2012-12-19 20:06 . 2011-01-13 02:51 6681088 ----a-w- c:\windows\system32\atidxx32.dll
2012-12-19 19:57 . 2012-12-19 19:57 442368 ----a-w- c:\windows\system32\atidemgy.dll
2012-12-19 19:56 . 2012-12-19 19:56 482304 ----a-w- c:\windows\system32\atieclxx.exe
2012-12-19 19:55 . 2012-12-19 19:55 219136 ----a-w- c:\windows\system32\atiesrxx.exe
2012-12-19 19:54 . 2012-12-19 19:54 163840 ----a-w- c:\windows\system32\atitmmxx.dll
2012-12-19 19:54 . 2012-12-19 19:54 20992 ----a-w- c:\windows\system32\atimuixx.dll
2012-12-19 19:54 . 2012-12-19 19:54 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2012-12-19 19:44 . 2011-01-13 02:23 4162048 ----a-w- c:\windows\system32\atiumdva.dll
2012-12-19 19:33 . 2012-12-19 19:33 56832 ----a-w- c:\windows\system32\atimpc32.dll
2012-12-19 19:33 . 2012-12-19 19:33 56832 ----a-w- c:\windows\system32\amdpcom32.dll
2012-12-19 19:33 . 2012-12-19 19:33 421888 ----a-w- c:\windows\system32\atiadlxx.dll
2012-12-19 19:33 . 2012-12-19 19:33 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-12-19 19:33 . 2012-12-19 19:33 33280 ----a-w- c:\windows\system32\atigktxx.dll
2012-12-19 19:32 . 2012-12-19 19:32 442368 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-12-19 19:31 . 2011-01-13 02:14 109568 ----a-w- c:\windows\system32\atiuxpag.dll
2012-12-19 19:30 . 2011-01-13 02:14 83968 ----a-w- c:\windows\system32\atiu9pag.dll
2012-12-19 19:30 . 2012-12-19 19:30 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-12-19 14:45 . 2012-12-19 14:45 180224 ----a-w- c:\windows\system32\clinfo.exe
2012-12-19 14:44 . 2012-12-19 14:44 65536 ----a-w- c:\windows\system32\OpenVideo.dll
2012-12-19 14:44 . 2012-12-19 14:44 56320 ----a-w- c:\windows\system32\OVDecode.dll
2012-12-19 14:38 . 2012-12-19 14:38 28732928 ----a-w- c:\windows\system32\amdocl.dll
2012-12-19 14:34 . 2012-12-19 14:34 50176 ----a-w- c:\windows\system32\OpenCL.dll
2012-12-16 14:13 . 2012-12-21 22:10 295424 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-21 22:10 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-14 14:13 . 2012-12-14 14:13 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-12-14 14:12 . 2011-05-31 17:29 22328 ----a-w- c:\users\Uzivatel\AppData\Roaming\PnkBstrK.sys
2012-11-14 02:09 . 2012-12-12 20:23 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58 . 2012-12-12 20:23 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57 . 2012-12-12 20:23 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49 . 2012-12-12 20:23 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48 . 2012-12-12 20:23 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44 . 2012-12-12 20:23 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-13 20:29 . 2012-11-13 20:29 354216 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
2012-11-09 04:42 . 2012-12-12 14:42 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-06 11:11 . 2012-11-06 11:11 84992 ----a-w- c:\windows\system32\drivers\AtihdW73.sys
2013-01-20 11:55 . 2012-10-20 09:56 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D} ----
.
2013-01-09 14:21 . 2013-01-09 14:21 114 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\instance.dat
2013-01-09 14:21 . 2013-01-09 14:21 0 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\{09274EEE-AE4E-42CF-848A-F8F53759B783}.native.bitness.log
2013-01-09 14:21 . 2013-01-09 14:21 0 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\{09274EEE-AE4E-42CF-848A-F8F53759B783}.native.data.log
2013-01-09 14:21 . 2013-01-09 14:21 0 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\{09274EEE-AE4E-42CF-848A-F8F53759B783}.native.elements.log
2013-01-09 14:21 . 2013-01-09 14:21 0 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\{09274EEE-AE4E-42CF-848A-F8F53759B783}.native.weight.log
2013-01-09 14:21 . 2013-01-09 14:21 0 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\minecraft-version-changer.lnk
2013-01-09 14:21 . 2013-01-09 14:21 633 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\minecraft-version-changer.dat
2013-01-09 14:21 . 2013-01-09 14:21 180 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\minecraft-version-changer.par
2013-01-09 14:21 . 2012-11-15 18:56 583792 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\mia.lib
2013-01-09 14:21 . 2012-11-15 18:56 5206913 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\minecraft-version-changer.res
2013-01-09 14:21 . 2012-11-15 18:56 290816 -c--a-w- c:\programdata\{13F6C219-94FE-48F3-A944-8AD2392D0C1D}\minecraft-version-changer.msi
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18705664]
"HydraVisionDesktopManager"="c:\program files\ATI Technologies\HydraVision\HydraDM.exe" [2011-01-12 393216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-07-28 9398888]
"DT ACR"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2009-08-24 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2012-01-19 17:08 3477312 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneVI]
2007-07-26 13:05 20480 ----a-w- c:\program files\GIGABYTE\ET6\ETcall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
.
R2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [x]
R2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\DRIVERS\wcmvcam.sys [x]
R3 AODDriver;AODDriver;c:\program files\GIGABYTE\ET6\i386\AODDriver.sys [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys [x]
R3 GemCCID;GemCCID;c:\windows\system32\Drivers\GemCCID.sys [x]
R3 MSICDSetup;MSICDSetup;E:\CDriver.sys [x]
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys [x]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys [x]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys [x]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys [x]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys [x]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys [x]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1018unic.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [x]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 13:55]
.
.
------- Doplňkový sken -------
.
mStart Page =
hxxp://www.google.comIE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 90.183.115.6 83.167.234.32
FF - ProfilePath - c:\users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\gc1oabgz.default-1347702598207\
FF - prefs.js: browser.startup.homepage -
www.seznam.cz.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1094803241-788000046-1805994050-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c7,75,84,e3,95,e3,c6,fd,89,dc,23,b7,ca,dd,bf,f9,b0,4a,d6,9a,5a,c8,b1,
77,b8,97,3b,26,6a,0a,06,74,2a,66,a4,f4,77,27,4a,fd,df,f8,a1,f3,ec,cf,4c,fc,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
.
[HKEY_USERS\S-1-5-21-1094803241-788000046-1805994050-1000\Software\SecuROM\License information*]
"datasecu"=hex:d5,66,0e,24,74,a0,ae,85,99,4a,8a,bb,b9,03,d5,37,09,d8,d9,3c,78,
38,35,a3,00,23,12,56,8b,ed,d2,a0,32,b4,4e,a4,c9,7a,fd,5b,89,90,d3,fe,a6,0c,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_USERS\S-1-5-21-1094803241-788000046-1805994050-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\c:\Users\Uzivatel\Desktop\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"qgif4.dll"=multi:"2011-10-10T17:42\00gif\00\00"
"qico4.dll"=multi:"2011-10-10T17:42\00ico\00\00"
"qjpeg4.dll"=multi:"2011-10-10T17:42\00jpeg\00jpg\00\00"
.
[HKEY_USERS\S-1-5-21-1094803241-788000046-1805994050-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:\c:\Users\Uzivatel\Desktop\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]
"qcncodecs4.dll"=multi:"2011-10-10T17:42\00GB18030\00GBK\00GB2312\00CP936\00MS936\00windows-936\00MIB: 114\00MIB: 113\00MIB: 2025\00\00"
"qkrcodecs4.dll"=multi:"2011-10-10T17:42\00EUC-KR\00cp949\00MIB: 38\00MIB: -949\00\00"
"qtwcodecs4.dll"=multi:"2011-10-10T17:42\00Big5\00Big5-HKSCS\00Big5-ETen\00CP950\00MIB: 2026\00MIB: 2101\00\00"
.
[HKEY_USERS\S-1-5-21-1094803241-788000046-1805994050-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\c:\users\Uzivatel\Desktop\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]
"qcncodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qjpcodecs4.dll"=multi:"40602\000\00Windows msvc release full-config\002011-10-10T17:42\00\00"
"qjpcodecsd4.dll"=multi:"40703\001\00Windows msvc debug full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qkrcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qtwcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
.
[HKEY_USERS\S-1-5-21-1094803241-788000046-1805994050-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\c:\users\Uzivatel\Desktop\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"Microsoft.VC80.CRT.manifest"=multi:"0\001\00unknown\002011-10-10T17:42\00\00"
"msvcr80.dll"=multi:"0\001\00unknown\002011-10-10T17:42\00\00"
"qgif4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qico4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qjpeg4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\atieclxx.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2013-02-03 17:44:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-03 16:44
ComboFix2.txt 2013-02-03 09:57
.
Před spuštěním: Volných bajtů: 372 000 886 784
Po spuštění: Volných bajtů: 372 008 882 176
.
- - End Of File - - FFE3AD4A7B6F4A897E0BA18E406C5CB0