ComboFix 17-05-16.01 - Jura 10.06.2017 17:31:10.2.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2276 [GMT 2:00]
Spuštěný z: c:\users\Jura\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jura\Desktop\CFScript.txt
AV: Avast Antivirus *Disabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
SP: Avast Antivirus *Disabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Spybot - Search & Destroy 2
c:\program files (x86)\Spybot - Search & Destroy 2\DelZip192.dll
c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe.log
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-install-bdupd-2017a.exe
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-install-iefreezefix.exe
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-install-wsc-update-a.exe
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-translation-hux2.exe
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-translation-nlx2.exe
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-updater-update.exe
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2017-05-10 do 2017-06-10 )))))))))))))))))))))))))))))))
.
.
2017-06-06 14:37 . 2017-06-06 14:37 203680 ----a-w- c:\windows\system32\drivers\zamguard64.sys
2017-06-06 14:37 . 2017-06-06 14:37 203680 ----a-w- c:\windows\system32\drivers\zam64.sys
2017-06-06 14:37 . 2017-06-06 14:37 -------- d-----w- c:\program files (x86)\Zemana AntiMalware
2017-06-06 14:34 . 2017-06-06 14:34 -------- d-----w- c:\users\Jura\AppData\Local\Zemana
2017-06-06 04:04 . 2017-06-06 04:04 -------- d-----w- C:\zoek
2017-06-03 13:17 . 2017-06-04 08:13 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-06-03 13:16 . 2017-06-03 13:32 -------- d-----w- c:\programdata\RogueKiller
2017-06-03 11:10 . 2017-06-03 11:10 -------- d-----w- c:\programdata\Sophos
2017-06-03 11:09 . 2017-06-03 11:09 -------- d-----w- c:\program files (x86)\Sophos
2017-05-30 19:46 . 2017-06-03 10:47 -------- d-----w- C:\AdwCleaner
2017-05-28 14:05 . 2017-05-28 14:05 -------- d-----w- c:\program files\Defraggler
2017-05-28 11:58 . 2017-05-28 11:58 -------- d-----w- c:\users\Jura\AppData\Local\Programs
2017-05-28 11:54 . 2017-05-28 11:54 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-06-10 15:36 . 2017-01-02 17:03 65536 ----a-w- c:\windows\system32\spu_storage.bin
2017-05-13 11:12 . 2017-01-02 19:16 158880 ----a-w- c:\windows\system32\drivers\aswstm.sys
2017-05-09 21:12 . 2017-04-29 17:19 803320 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2017-05-09 21:12 . 2017-04-29 17:19 144888 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2017-05-09 17:53 . 2017-01-02 19:16 339696 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2017-05-09 17:53 . 2017-05-09 17:54 400456 ----a-w- c:\windows\system32\aswBoot.exe
2017-05-09 17:53 . 2017-01-02 19:16 569192 ----a-w- c:\windows\system32\drivers\aswSP.sys
2017-05-09 17:53 . 2017-01-02 19:16 75704 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2017-05-09 17:53 . 2017-01-02 19:16 128648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2017-05-09 17:53 . 2017-01-02 19:16 38296 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2017-05-09 17:53 . 2017-01-02 19:16 101152 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2017-05-09 17:53 . 2017-01-02 19:17 32600 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2017-05-09 17:53 . 2017-01-02 19:16 1007160 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2017-05-09 17:53 . 2017-04-04 18:10 49016 ----a-w- c:\windows\system32\drivers\aswbuniva.sys
2017-05-09 17:53 . 2017-04-04 18:10 334576 ----a-w- c:\windows\system32\drivers\aswbloga.sys
2017-05-09 17:53 . 2017-04-04 18:10 311808 ----a-w- c:\windows\system32\drivers\aswbidsdrivera.sys
2017-05-09 17:53 . 2017-04-04 18:10 190256 ----a-w- c:\windows\system32\drivers\aswbidsha.sys
2017-03-12 21:03 . 2017-03-12 21:15 409128 ----a-w- c:\windows\SysWow64\EasyAntiCheat.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2017-05-05 9772248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-06 642216]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 aswbIDSAgent;aswbIDSAgent;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe [x]
R3 aswHwid;aswHwid;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
S0 aswbidsh;aswbidsh;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys [x]
S0 aswblog;aswblog;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys [x]
S0 aswbuniv;aswbuniv;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys [x]
S0 aswRvrt;aswRvrt;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys [x]
S0 aswVmm;aswVmm;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys [x]
S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdrivera.sys;c:\windows\SYSNATIVE\drivers\aswbidsdrivera.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 ZAM;ZAM Helper Driver;c:\windows\System32\drivers\zam64.sys;c:\windows\SYSNATIVE\drivers\zam64.sys [x]
S1 ZAM_Guard;ZAM Guard Driver;c:\windows\System32\drivers\zamguard64.sys;c:\windows\SYSNATIVE\drivers\zamguard64.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 ZAMSvc;ZAM Controller Service;c:\program files (x86)\Zemana AntiMalware\ZAM.exe;c:\program files (x86)\Zemana AntiMalware\ZAM.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2017-05-09 17:53 1505952 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2017-05-09 17:53 1505952 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvLaunch.exe" [2017-05-09 213824]
"ZAM"="c:\program files (x86)\Zemana AntiMalware\ZAM.exe" [2017-04-03 14522512]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
https://www.google.com/?bcutc=sp-006mStart Page =
https://www.google.com/?bcutc=sp-006mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page =
https://www.google.com/search?bcutc=sp-006&q={searchTerms}
mSearch Bar =
https://www.google.com/?bcutc=sp-006TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Jura\AppData\Roaming\Mozilla\Firefox\Profiles\382egtg4.default-1496720912187\
FF - prefs.js: browser.startup.homepage - google.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-{050d4fc8-5d48-4b8f-8972-47c82c46020f} - c:\programdata\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
AddRemove-{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} - c:\programdata\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
AddRemove-{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} - c:\programdata\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
.
**************************************************************************
.
Celkový čas: 2017-06-10 17:39:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2017-06-10 15:39
ComboFix2.txt 2017-06-08 15:32
.
Před spuštěním: Volných bajtů: 363 194 093 568
Po spuštění: Volných bajtů: 363 099 340 800
.
- - End Of File - - CA0B6B2D5F578796BD5795056F69FFA7
A36C5E4F47E84449FF07ED3517B43A31