12:59:06.0213 3104 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
12:59:06.0229 3104 TDTCP - ok
12:59:06.0260 3104 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:59:06.0276 3104 tdx - ok
12:59:06.0307 3104 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
12:59:06.0307 3104 TermDD - ok
12:59:06.0370 3104 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
12:59:06.0401 3104 TermService - ok
12:59:06.0416 3104 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
12:59:06.0432 3104 Themes - ok
12:59:06.0479 3104 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
12:59:06.0479 3104 THREADORDER - ok
12:59:06.0510 3104 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
12:59:06.0510 3104 TrkWks - ok
12:59:06.0651 3104 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:59:06.0666 3104 TrustedInstaller - ok
12:59:06.0698 3104 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
12:59:06.0729 3104 tssecsrv - ok
12:59:06.0885 3104 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
12:59:06.0901 3104 TsUsbFlt - ok
12:59:06.0963 3104 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:59:06.0979 3104 tunnel - ok
12:59:06.0995 3104 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
12:59:07.0010 3104 uagp35 - ok
12:59:07.0120 3104 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:59:07.0135 3104 udfs - ok
12:59:07.0166 3104 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:59:07.0182 3104 UI0Detect - ok
12:59:07.0229 3104 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
12:59:07.0229 3104 uliagpkx - ok
12:59:07.0307 3104 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
12:59:07.0323 3104 umbus - ok
12:59:07.0385 3104 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
12:59:07.0401 3104 UmPass - ok
12:59:07.0479 3104 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
12:59:07.0495 3104 UmRdpService - ok
12:59:07.0526 3104 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
12:59:07.0541 3104 upnphost - ok
12:59:07.0604 3104 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
12:59:07.0604 3104 usbccgp - ok
12:59:07.0651 3104 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
12:59:07.0666 3104 usbcir - ok
12:59:07.0713 3104 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
12:59:07.0729 3104 usbehci - ok
12:59:07.0838 3104 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
12:59:07.0854 3104 usbhub - ok
12:59:07.0916 3104 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
12:59:07.0932 3104 usbohci - ok
12:59:08.0010 3104 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
12:59:08.0041 3104 usbprint - ok
12:59:08.0104 3104 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
12:59:08.0120 3104 usbscan - ok
12:59:08.0182 3104 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:59:08.0182 3104 USBSTOR - ok
12:59:08.0245 3104 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
12:59:08.0245 3104 usbuhci - ok
12:59:08.0307 3104 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
12:59:08.0307 3104 UxSms - ok
12:59:08.0370 3104 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
12:59:08.0370 3104 VaultSvc - ok
12:59:08.0401 3104 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
12:59:08.0401 3104 vdrvroot - ok
12:59:08.0479 3104 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
12:59:08.0495 3104 vds - ok
12:59:08.0541 3104 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
12:59:08.0557 3104 vga - ok
12:59:08.0573 3104 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
12:59:08.0573 3104 VgaSave - ok
12:59:08.0635 3104 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
12:59:08.0635 3104 vhdmp - ok
12:59:08.0666 3104 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
12:59:08.0682 3104 viaide - ok
12:59:08.0713 3104 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
12:59:08.0713 3104 vmbus - ok
12:59:08.0745 3104 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
12:59:08.0745 3104 VMBusHID - ok
12:59:08.0776 3104 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
12:59:08.0791 3104 volmgr - ok
12:59:08.0838 3104 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:59:08.0838 3104 volmgrx - ok
12:59:08.0885 3104 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
12:59:08.0885 3104 volsnap - ok
12:59:08.0948 3104 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
12:59:08.0963 3104 vsmraid - ok
12:59:09.0057 3104 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
12:59:09.0120 3104 VSS - ok
12:59:09.0135 3104 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
12:59:09.0135 3104 vwifibus - ok
12:59:09.0166 3104 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
12:59:09.0182 3104 W32Time - ok
12:59:09.0213 3104 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
12:59:09.0213 3104 WacomPen - ok
12:59:09.0260 3104 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
12:59:09.0291 3104 WANARP - ok
12:59:09.0307 3104 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:59:09.0307 3104 Wanarpv6 - ok
12:59:09.0370 3104 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
12:59:09.0432 3104 WatAdminSvc - ok
12:59:09.0588 3104 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
12:59:09.0620 3104 wbengine - ok
12:59:09.0651 3104 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
12:59:09.0666 3104 WbioSrvc - ok
12:59:09.0713 3104 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:59:09.0729 3104 wcncsvc - ok
12:59:09.0760 3104 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:59:09.0776 3104 WcsPlugInService - ok
12:59:09.0807 3104 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
12:59:09.0823 3104 Wd - ok
12:59:09.0963 3104 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:59:09.0995 3104 Wdf01000 - ok
12:59:10.0026 3104 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:59:10.0026 3104 WdiServiceHost - ok
12:59:10.0041 3104 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:59:10.0041 3104 WdiSystemHost - ok
12:59:10.0073 3104 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
12:59:10.0073 3104 WebClient - ok
12:59:10.0120 3104 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:59:10.0120 3104 Wecsvc - ok
12:59:10.0135 3104 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:59:10.0151 3104 wercplsupport - ok
12:59:10.0198 3104 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
12:59:10.0198 3104 WerSvc - ok
12:59:10.0260 3104 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
12:59:10.0260 3104 WfpLwf - ok
12:59:10.0276 3104 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
12:59:10.0323 3104 WIMMount - ok
12:59:10.0338 3104 WinDefend - ok
12:59:10.0354 3104 WinHttpAutoProxySvc - ok
12:59:11.0291 3104 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:59:11.0307 3104 Winmgmt - ok
12:59:11.0416 3104 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
12:59:11.0479 3104 WinRM - ok
12:59:11.0541 3104 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
12:59:11.0588 3104 WinUsb - ok
12:59:11.0651 3104 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
12:59:11.0666 3104 Wlansvc - ok
12:59:11.0682 3104 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
12:59:11.0682 3104 WmiAcpi - ok
12:59:11.0713 3104 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:59:11.0713 3104 wmiApSrv - ok
12:59:11.0729 3104 WMPNetworkSvc - ok
12:59:11.0760 3104 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
12:59:11.0760 3104 WPCSvc - ok
12:59:11.0791 3104 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:59:11.0791 3104 WPDBusEnum - ok
12:59:11.0838 3104 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:59:11.0838 3104 ws2ifsl - ok
12:59:11.0870 3104 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
12:59:11.0870 3104 wscsvc - ok
12:59:11.0885 3104 WSearch - ok
12:59:12.0104 3104 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
12:59:12.0151 3104 wuauserv - ok
12:59:12.0198 3104 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
12:59:12.0198 3104 WudfPf - ok
12:59:12.0307 3104 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
12:59:12.0338 3104 WUDFRd - ok
12:59:12.0370 3104 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:59:12.0385 3104 wudfsvc - ok
12:59:12.0416 3104 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
12:59:12.0432 3104 WwanSvc - ok
12:59:12.0604 3104 [ E1E858AEF2ED420CBB7605D3ECCEC69A ] yukonw7 C:\Windows\system32\DRIVERS\yk62x64.sys
12:59:12.0620 3104 yukonw7 - ok
12:59:12.0635 3104 ================ Scan global ===============================
12:59:12.0682 3104 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
12:59:12.0776 3104 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
12:59:12.0791 3104 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
12:59:12.0838 3104 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
12:59:12.0901 3104 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
12:59:12.0901 3104 [Global] - ok
12:59:12.0901 3104 ================ Scan MBR ==================================
12:59:12.0916 3104 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2
12:59:13.0057 3104 \Device\Harddisk2\DR2 - ok
12:59:13.0291 3104 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:59:13.0760 3104 \Device\Harddisk0\DR0 - ok
12:59:13.0776 3104 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
12:59:13.0776 3104 \Device\Harddisk1\DR1 - ok
12:59:13.0776 3104 ================ Scan VBR ==================================
12:59:13.0791 3104 [ 53DD8B267762DB5B3436BC0BC542FB1C ] \Device\Harddisk2\DR2\Partition1
12:59:13.0791 3104 \Device\Harddisk2\DR2\Partition1 - ok
12:59:13.0807 3104 [ 77DA5F837A07005F5431D5A9AB81A275 ] \Device\Harddisk2\DR2\Partition2
12:59:13.0807 3104 \Device\Harddisk2\DR2\Partition2 - ok
12:59:13.0807 3104 [ 9FF0B7B68F9E3B61941E8ACB18A3D824 ] \Device\Harddisk0\DR0\Partition1
12:59:13.0807 3104 \Device\Harddisk0\DR0\Partition1 - ok
12:59:13.0823 3104 [ 587F98547B42017C378338AAB8095998 ] \Device\Harddisk0\DR0\Partition2
12:59:13.0823 3104 \Device\Harddisk0\DR0\Partition2 - ok
12:59:13.0838 3104 [ 69B6FF925FED92F02CC726A87E2788B4 ] \Device\Harddisk1\DR1\Partition1
12:59:13.0838 3104 \Device\Harddisk1\DR1\Partition1 - ok
12:59:13.0838 3104 ============================================================
12:59:13.0838 3104 Scan finished
12:59:13.0838 3104 ============================================================
12:59:13.0870 2620 Detected object count: 0
12:59:13.0870 2620 Actual detected object count: 0
12:59:55.0651 3752 Deinitialize success
COMBOFIX LOG:
ComboFix 13-02-07.02 - Felipe Grande 09.02.2013 13:06:38.4.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4095.2760 [GMT 1:00]
Spuštěný z: c:\users\Felipe Grande\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-09 do 2013-02-09 )))))))))))))))))))))))))))))))
.
.
2013-02-09 12:14 . 2013-02-09 12:14 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-02-09 12:14 . 2013-02-09 12:14 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp
2013-02-09 12:14 . 2013-02-09 12:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-09 11:35 . 2013-02-09 11:35 -------- d-----w- c:\users\Felipe Grande\AppData\Local\Comodo
2013-02-08 15:20 . 2013-02-08 15:20 -------- d-----w- c:\users\Felipe Grande\AppData\Local\ACD Systems
2013-02-08 15:11 . 2013-02-08 19:52 -------- d-----w- c:\users\Felipe Grande\AppData\Local\Adobe
2013-02-08 11:02 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{037B66C2-64D8-4FAB-BAD8-0B16C46952F0}\mpengine.dll
2013-02-01 20:55 . 2013-02-01 20:55 -------- d-----w- c:\users\Felipe Grande\AppData\Local\Programs
2013-01-30 21:10 . 2013-01-30 21:15 -------- d-----w- c:\users\Felipe Grande\AppData\Roaming\BID
2013-01-30 21:10 . 2013-01-30 21:10 -------- d-----w- c:\program files (x86)\Bulk Image Downloader
2013-01-21 22:42 . 2013-01-21 22:42 -------- d-----w- c:\users\Felipe Grande\AppData\Roaming\NCH Software
2013-01-21 22:41 . 2013-01-21 22:41 -------- d-----w- c:\programdata\NCH Swift Sound
2013-01-21 22:40 . 2013-01-21 22:40 -------- d-----w- c:\program files (x86)\NCH Swift Sound
2013-01-21 22:40 . 2013-01-21 22:40 -------- d-----w- c:\users\Felipe Grande\AppData\Roaming\NCH Swift Sound
2013-01-19 14:22 . 2013-01-19 14:22 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2013-01-19 14:18 . 2013-01-19 14:18 -------- d-----r- C:\MSOCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-17 00:28 . 2012-01-28 02:29 273840 ------w- c:\windows\system32\MpSigStub.exe
2013-01-10 02:09 . 2012-01-28 16:37 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-17 15:14 . 2012-12-17 15:14 289768 ----a-w- c:\windows\system32\javaws.exe
2012-12-17 15:14 . 2012-12-17 15:14 189416 ----a-w- c:\windows\system32\javaw.exe
2012-12-17 15:14 . 2012-12-17 15:14 188904 ----a-w- c:\windows\system32\java.exe
2012-12-17 15:14 . 2012-12-17 15:14 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-12-17 15:14 . 2012-10-13 09:18 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-12-17 15:14 . 2012-10-13 09:18 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-12-17 15:13 . 2012-12-17 15:13 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-12-17 15:13 . 2012-12-17 15:13 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-12-17 15:13 . 2012-01-25 03:07 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-12-17 15:11 . 2012-04-08 09:13 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-12-17 15:11 . 2012-01-24 16:58 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-16 17:11 . 2012-12-22 02:00 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-22 02:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-22 02:00 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-22 02:00 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-14 15:49 . 2012-03-11 09:27 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-07 13:20 . 2013-01-09 20:57 441856 ----a-w- c:\windows\system32\Wpc.dll
2012-12-07 13:15 . 2013-01-09 20:57 2746368 ----a-w- c:\windows\system32\gameux.dll
2012-12-07 12:26 . 2013-01-09 20:57 308736 ----a-w- c:\windows\SysWow64\Wpc.dll
2012-12-07 12:20 . 2013-01-09 20:57 2576384 ----a-w- c:\windows\SysWow64\gameux.dll
2012-12-07 11:20 . 2013-01-09 20:57 30720 ----a-w- c:\windows\system32\usk.rs
2012-12-07 11:20 . 2013-01-09 20:57 43520 ----a-w- c:\windows\system32\csrr.rs
2012-12-07 11:20 . 2013-01-09 20:57 23552 ----a-w- c:\windows\system32\oflc.rs
2012-12-07 11:20 . 2013-01-09 20:57 45568 ----a-w- c:\windows\system32\oflc-nz.rs
2012-12-07 11:20 . 2013-01-09 20:57 44544 ----a-w- c:\windows\system32\pegibbfc.rs
2012-12-07 11:20 . 2013-01-09 20:57 20480 ----a-w- c:\windows\system32\pegi-fi.rs
2012-12-07 11:20 . 2013-01-09 20:57 20480 ----a-w- c:\windows\system32\pegi-pt.rs
2012-12-07 11:19 . 2013-01-09 20:57 20480 ----a-w- c:\windows\system32\pegi.rs
2012-12-07 11:19 . 2013-01-09 20:57 46592 ----a-w- c:\windows\system32\fpb.rs
2012-12-07 11:19 . 2013-01-09 20:57 40960 ----a-w- c:\windows\system32\cob-au.rs
2012-12-07 11:19 . 2013-01-09 20:57 15360 ----a-w- c:\windows\system32\djctq.rs
2012-12-07 11:19 . 2013-01-09 20:57 21504 ----a-w- c:\windows\system32\grb.rs
2012-12-07 11:19 . 2013-01-09 20:57 55296 ----a-w- c:\windows\system32\cero.rs
2012-12-07 11:19 . 2013-01-09 20:57 51712 ----a-w- c:\windows\system32\esrb.rs
2012-12-07 10:46 . 2013-01-09 20:57 43520 ----a-w- c:\windows\SysWow64\csrr.rs
2012-12-07 10:46 . 2013-01-09 20:57 30720 ----a-w- c:\windows\SysWow64\usk.rs
2012-12-07 10:46 . 2013-01-09 20:57 45568 ----a-w- c:\windows\SysWow64\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 20:57 44544 ----a-w- c:\windows\SysWow64\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 20:57 20480 ----a-w- c:\windows\SysWow64\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 20:57 23552 ----a-w- c:\windows\SysWow64\oflc.rs
2012-12-07 10:46 . 2013-01-09 20:57 20480 ----a-w- c:\windows\SysWow64\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 20:57 46592 ----a-w- c:\windows\SysWow64\fpb.rs
2012-12-07 10:46 . 2013-01-09 20:57 20480 ----a-w- c:\windows\SysWow64\pegi.rs
2012-12-07 10:46 . 2013-01-09 20:57 21504 ----a-w- c:\windows\SysWow64\grb.rs
2012-12-07 10:46 . 2013-01-09 20:57 40960 ----a-w- c:\windows\SysWow64\cob-au.rs
2012-12-07 10:46 . 2013-01-09 20:57 15360 ----a-w- c:\windows\SysWow64\djctq.rs
2012-12-07 10:46 . 2013-01-09 20:57 55296 ----a-w- c:\windows\SysWow64\cero.rs
2012-12-07 10:46 . 2013-01-09 20:57 51712 ----a-w- c:\windows\SysWow64\esrb.rs
2012-12-01 14:59 . 2012-12-01 14:59 724888 ----a-r- c:\users\Felipe Grande\AppData\Roaming\Microsoft\Installer\{4FF6A18E-1C17-4C48-8371-09C40B7ABFE9}\IconTmpl6.1992E333_D17A_448B_8484_ED047109D182.exe
2012-12-01 14:59 . 2012-12-01 14:59 212480 ----a-r- c:\users\Felipe Grande\AppData\Roaming\Microsoft\Installer\{4FF6A18E-1C17-4C48-8371-09C40B7ABFE9}\IconTmpl2.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2012-12-01 14:59 . 2012-12-01 14:59 2078096 ----a-r- c:\users\Felipe Grande\AppData\Roaming\Microsoft\Installer\{4FF6A18E-1C17-4C48-8371-09C40B7ABFE9}\IconTmpl4.1992E333_D17A_448B_8484_ED047109D182.exe
2012-11-30 05:45 . 2013-01-09 20:57 362496 ----a-w- c:\windows\system32\wow64win.dll
2012-11-30 05:45 . 2013-01-09 20:57 243200 ----a-w- c:\windows\system32\wow64.dll
2012-11-30 05:45 . 2013-01-09 20:57 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2012-11-30 05:45 . 2013-01-09 20:57 215040 ----a-w- c:\windows\system32\winsrv.dll
2012-11-30 05:43 . 2013-01-09 20:57 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2012-11-30 05:41 . 2013-01-09 20:57 424448 ----a-w- c:\windows\system32\KernelBase.dll
2012-11-30 05:41 . 2013-01-09 20:57 1161216 ----a-w- c:\windows\system32\kernel32.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-11-30 05:38 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-11-30 04:54 . 2013-01-09 20:57 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2012-11-30 04:53 . 2013-01-09 20:57 274944 ----a-w- c:\windows\SysWow64\KernelBase.dll
2012-11-30 04:45 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 20:57 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PrtScr by FireStarter"="c:\program files (x86)\PrtScr\PrtScr.exe" [2008-03-19 1375744]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-19 3477312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-09-07 348664]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
.
c:\users\Felipe Grande\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
Stardock ObjectDock.lnk - c:\program files (x86)\Stardock\ObjectDockFree\ObjectDock.exe [2010-10-6 3768176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-11-01 1431888]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2012-02-03 13352]
R3 IObitUnlocker;IObitUnlocker;c:\program files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [2011-03-09 33184]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [2012-03-14 13920]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-25 1255736]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-09-15 27760]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2011-02-02 18656]
S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2011-01-19 2078096]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2011-09-21 21992]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-11-05 375728]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2011-01-11 15928]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-01-25 3136328]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-26 283200]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2011-09-14 398112]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-01 06:54 1607120 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-20 c:\windows\Tasks\AdobeAAMUpdater-1.0-FM_workstation-Felipe Grande.job
- c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-03-14 02:44]
.
2012-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cdbb4da02a08d8.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-25 03:41]
.
2012-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-25 03:41]
.
2012-09-14 c:\windows\Tasks\{5B847F59-12D6-4753-A9A9-33EAF03E0366}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2010-09-02 13:15]
.
2012-09-14 c:\windows\Tasks\{7B95DF1F-6DAA-4C00-AF78-755F60F9CE66}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2010-09-02 13:15]
.
2012-09-14 c:\windows\Tasks\{F8EFB556-EBB3-422B-AFE1-A139FC917E15}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-06-10 15:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Felipe Grande\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-17 18:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-10-16 00:42 480888 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-10-16 00:42 480888 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-10-16 00:42 480888 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-10-16 00:42 480888 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-13 13374568]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2011-01-11 57928]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2011-01-25 4012360]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\acaptuser64.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
hxxp://www.ceskatelevize.cz/ivysilani/mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: En&queue current page with BID -
file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm
IE: Enqueue link target with BID -
file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm
IE: Open &link target with BID -
file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm
IE: Open current page with BID -
file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebid.htm
IE: Open current page with BID Link Explorer -
file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm
TCP: DhcpNameServer = 147.32.110.1 147.32.110.2
FF - ProfilePath - c:\users\Felipe Grande\AppData\Roaming\Mozilla\Firefox\Profiles\6w4x7wh6.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.centrum.cz/FF - ExtSQL: 2013-01-30 21:58;
doubleclick-picture@windpr.tw; c:\users\Felipe Grande\AppData\Roaming\Mozilla\Firefox\Profiles\6w4x7wh6.default\extensions\doubleclick-picture@windpr.tw.xpi
FF - ExtSQL: 2013-01-30 21:58;
imagedownload@Merci.chao; c:\users\Felipe Grande\AppData\Roaming\Mozilla\Firefox\Profiles\6w4x7wh6.default\extensions\imagedownload@Merci.chao.xpi
FF - ExtSQL: 2013-01-30 22:07; {524B8EF8-C312-11DB-8039-536F56D89593}; c:\users\Felipe Grande\AppData\Roaming\Mozilla\Firefox\Profiles\6w4x7wh6.default\extensions\{524B8EF8-C312-11DB-8039-536F56D89593}.xpi
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1193739700-1416340202-3985265929-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10o\UserChoice]
@Denied: (2) (S-1-5-21-1193739700-1416340202-3985265929-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.v10o"
.
[HKEY_USERS\S-1-5-21-1193739700-1416340202-3985265929-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10p\UserChoice]
@Denied: (2) (S-1-5-21-1193739700-1416340202-3985265929-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.v10p"
.
[HKEY_USERS\S-1-5-21-1193739700-1416340202-3985265929-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10pf\UserChoice]
@Denied: (2) (S-1-5-21-1193739700-1416340202-3985265929-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.v10pf"
.
[HKEY_USERS\S-1-5-21-1193739700-1416340202-3985265929-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (S-1-5-21-1193739700-1416340202-3985265929-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.xmp"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="181C3CC3EFEA5B78DD9CE2F0A59D0D2A81E9412D60C4ABCA89FC491004278486AC0CBE9658347B9EE9C88A8E45C4C8A1711FF08BE86711275C108AF971424AAA35178E3254FCECE5D1A07125C9BF7DC87A91D19920C8DB78625B34F259816B6670A48E0D203205ED58FEA8A7043EBE8703AD405F0C767C90C57B113A9674D515ECA297418A06CD3A12C13327D7B3D22CC5E20E0AC54715A207125F3817712B731083738EF6EF8532E84C095DBD56356550A47F6AFAD17D4B7AC2D0F55C10BC2593BC60575D2A1BFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98085D575E7D6A3B9808A6171C11EC38DE3D9DB7CE019D40AA5C99301CB82A91B5425E00CC559039F59406A702939CA7436F1379C1EAC2616EB562C0743B19942CAA82C94F90F4BC83A713BFC6C8142E519D38C917775961516C9B905BA615933E83827B32E45FB9005D6DD2F51E053DEB3CC92182497F8F9344366C0BE57F0B1D5AD7C582490C1FBCE0B5188FB623D726B23257945201A528008775C6D65F07C0EE602D522857714F8CF59995ABC716D79AC21D607750F04899C81E51CBDE2B5EB55F0A3961C6C693F497B28F886C251BC131F4FD1280D26F3A972EF488C9ACF6567A894D48FE4B275EEB18074E3244CFAC94B4896E4C41DF4375C1FCC99357C8AFBC2D2F22CCBCEAC2A4CE8B6E5DC99890E809A14D0F449AC647C8B93DD208D9D015C8FD2C1D70074F5A2FAFD3561BDCD7106EE9E5CA79698CD78682043FB173FED3066215054CE46508E789D9A6B6C7A14D390CDDA493D810D2922D3339DAA3B03161047D3ACBB11B0DFAB34E01AB4840C91030D563D5B702C9DA17D7401D3A94C72A107F18FEDFB92DBE4DF7379F913A116D0ADB769A9B44341CA16CFB284D8B1407B9249B88A63E0FDA798E43C89B49149F4AF66D4E5BEE68EB30E535BBB4A779EFB6EBEA207F5A3ECFDD3C3FF421DD27CAA81FFD7314CEA6B1ACA95B300FB340B13FC8CA10A874AA6D26A2EB04A09882E36242809EA6E10F28048F7FEE3C2C90EC12A1A7392425275A80D4AB6A5DD1C237B6C071F835DBA5E1A568D677E2BF7818F0D10E0DB73B6B101F5C88B0DF9168E2686F7340A92556BF07743CDA6B546C799FA8B213EE3613DCB8B3ADF2F19857593F1749C5AED76D7A9F6B2DBE8202C12F6A69EB6817CC1E61884B6A602259596209F55C6EB5C59C9EED754BDF9996B2A91DC9B53BC1E9ED144D07B43EC5F89897923C3A33716F788BF1B15D0AE611DD2D8AF6ACCD45A84CBEC8BFA16571D228E8308E94A1DB0FFAF3AF31CBA061A545D4870E15F83D5B620042C0ED4182F47998BA87BDDBAF8E81E02F7B2798C8BDCF0A6DA2D6278587C148054BF9529722E7BC8CB2B116ED8E4DAD00891EFE1C76C7"
"OODEFRAG14.00.00.01PROFESSIONAL"="D20C90ED580EDAFBCA309636E2FE3F07FBC1215AA62081F2227E92FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D1407A9C6AECB7A5D1407A9C6AECB7A5D1407D57E0EE69335AE6DA40C3C0A0AFEF7133C75836F649F00C9116E170C8D13AA5F3F81B297AB6F95C88722F0F182BC200298BD030EACD6C40C316DAE711ED840ED082C9DBF79A889C908A6FEDF30061D0B638CF9A47CA99393E507E90C257B098B2AA7F3908DD5572F91FA62059FD59F3A921F57847DBC205ED36FCF6F86E75E49193FEF7CAB4A9E3781A427D4130AAC2212519C438E19F56E12FD7572DF6CEF39B9E4DD3D4B40D1A8AACEF08A7D659B584127E23C4027714BAEAE08B07E40C074632E9F4F9754BACBD146F4A1088E9A7771C8558D57B9C5FE2721490AE3F8261664522AF07108736C317E7F5C0F0FAB1BEB80B2984F81F698F01B8B9FC7154DBDFEAF062769426CDBF60BEC4023D59FE66ABBCD84D396E02BF302395A15F3338EE447D23ACA4A68EDC5A63094083523809B0F0F3BC6F42F4C8B634D64E8D9AAB0C1BC3F378D4E817C33315067B7E4B18FA331F06ABEFBE41709EDD7AD96EF5B5032D8126CE3E0A1E2C8AAE68A5DFC1BC2987B0383046E572A2FF67CE8A442BF1DC60A24EF30750903063822135AFD054C06EEE83E94F331273674F50D4E4125C80560631889E54C415BA5C3D9434868E1E9AD58142218EEB7CB840ED40141B10E65114F82BC7152852F60A27BDF24123C39FD1FC2124AE3048CE5A6C0DEFAD8A554747E8F4838D63C5B78A9DA2D3AA11AD9CB1ACDFD5DB4BA117CB3133F0BE6D0B4879B61DF3E69582FA6561B5C9A8DBB27263E793489DA8FDC503D53AD707AD35AEB6162EAEE6F4BEB43BB2551379DE7EF3E1251B3EA24B8EE8D5F4CE69085F30FE621BC06979E11C74C7E28A3E56EE8F6EBB0A3B4FE347036834A0DDDB3D07E8D5FC262806803A36C64DA94A061F18AF22A4A01A0A97E7597A642693A07F4C30B63BC06DBF7FD8477501E9EC948EA1F901921C192B34E0C690EA0F85599E11728A41FA0D1BE42B87B7B2AC0D21C747CEC790DFDDEC6C0F7F876D015BD615ACE017688ED4D9A57C8FEF17537A444797D1CB379140A73480707C0535E373575C62153AE6EEDCC1941FAE68B83DA0BBBFDA55165284C2DA885466E3BB6B6D11CDF89565CE6067A38B25E3088EAC61ECF600303649E94C9FDC65E28B2C567580F7D2F426DDD9EAD38B10BC6A0F5EB901F0B249A9CA1050736A1EBBBF478A8CC60867C7BD4217354EE57D6C999F184596466EC8FCA20718211F00016D2FB8B9777674E0A95BFF13E8B3F0BF94DF07B51B3DF327A3DCC64C025139DCD304357858E8E739BCA8EBF210B8B67BEAA4772376EE9C19DD79B1B"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
Celkový čas: 2013-02-09 13:17:22
ComboFix-quarantined-files.txt 2013-02-09 12:17
ComboFix2.txt 2012-11-22 15:06
.
Před spuštěním: Volných bajtů: 18 934 804 480
Po spuštění: Volných bajtů: 18 862 260 224
.
- - End Of File - - 3A1EB566627095D27BFB084E907B6580