Cus, vyskytlo se par problemu, po smazani dvou nalezu z roguekilleru (adresa podobna mojemu konfigu) mi presel fungovat intenet, tak jsem musel dat restore, a u zemana po skenu jsem dal dalsi a autoamticky to se clearlo, ale asi vklidu xD
RogueKiller V12.11.26.0 (x64) [Nov 27 2017] (Free) by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
https://forum.adlice.comWebová stránka :
http://www.adlice.com/download/roguekiller/Blog :
http://www.adlice.comOperační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Petr [Práva správce]
Started from : C:\Users\PetrDownloads\RogueKiller_portable64.exe
Mód : Smazat -- Datum : 11/28/2017 02:10:38 (Duration : 00:15:25)
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{9317833D-D4B3-4B9C-8B06-9B224515606B} | NameServer : 94.74.192.252,8.8.8.8 ([Czech Republic][-]) -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{9317833D-D4B3-4B9C-8B06-9B224515606B} | NameServer : 94.74.192.252,8.8.8.8 ([Czech Republic][-]) -> Nahrazeno ()
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD10EZEX-00BN5A0 ATA Device +++++
--- User ---
[MBR] b96e826721bf05997f6261b4b233f62f
[BSP] de8104dc4ad33b6866b6dc0a259f12a3 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 208848 | Size: 953767 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
Zoek.exe v5.0.0.1 Updated 24-October-2017
Tool run by Petr on st 29.11.2017 at 0:42:58,76.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Petr\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
29.11.2017 0:43:45 Zoek.exe System Restore Point Created Successfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
HKCU\SearchScopes\{39ED13E7-4C0C-43E1-AA3C-35BD10C9E056} -
http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_29530
==== Reset Google Chrome ======================
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data-journal was reset successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Data aplikací\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=0 folders=0 0 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Petr\AppData\Local\Temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Windows\TEMP successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 29.11.2017 at 0:45:49,42 ======================
Zemana AntiMalware 2.74.2.150 (instalační verze)
-------------------------------------------------------
Scan Result : Dokončeno
Scan Date : 2017.11.29
Operating System : Windows 7 64-bit
Processor : 4X AMD Athlon(tm) II X4 640 Processor
BIOS Mode : Legacy
CUID : 12B0FA295BE39D443A003C
Scan Type : Skenování systému
Duration : 11m 24s
Scanned Objects : 83188
Detected Objects : 1
Excluded Objects : 0
Read Level : SCSI
Auto Upload : Zapnuto
Detect All Extensions : Vypnuto
Scan Documents : Vypnuto
Domain Info : WORKGROUP,0,2
Detected Objects
-------------------------------------------------------
Chrome Shortcut
Status : Skenováno
Object : --app=http://go.playmmogames.com/aff_c?offer_id=1508&aff_id=1034&source=1&click_id=0005d2cb4cbac4c6f9bee9b6e13c326bdf1a5b38
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Podezřelé nastavení prohlížeče
Cleaning Action : Opravit
Related Objects :
Nastavení prohlížeče - Chrome Shortcut
Cleaning Result
-------------------------------------------------------
Cleaned : 1
Reported as safe : 0
Failed : 0
ComboFix 17-11-14.01 - Petr 29.11.2017 1:07.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4094.2144 [GMT 1:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.pol
c:\users\PetrDownloads\RogueKiller_portable64.exe
c:\windows\security\logs\scecomp.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2017-10-28 do 2017-11-29 )))))))))))))))))))))))))))))))
.
.
2017-11-29 00:13 . 2017-11-29 00:13 -------- d-----w- c:\users\Public\AppData\Local\temp
2017-11-29 00:13 . 2017-11-29 00:13 -------- d-----w- c:\users\Petr\AppData\Local\temp
2017-11-29 00:13 . 2017-11-29 00:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-11-29 00:07 . 2017-11-29 00:07 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{68A75D7B-7097-4CE6-A57F-4C6D4CEEF6A2}\offreg.892.dll
2017-11-29 00:05 . 2017-10-30 09:27 13771264 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{68A75D7B-7097-4CE6-A57F-4C6D4CEEF6A2}\mpengine.dll
2017-11-28 23:48 . 2017-11-28 23:48 203680 ----a-w- c:\windows\system32\drivers\zamguard64.sys
2017-11-28 23:48 . 2017-11-28 23:48 203680 ----a-w- c:\windows\system32\drivers\zam64.sys
2017-11-28 23:48 . 2017-11-28 23:48 -------- d-----w- c:\program files (x86)\Zemana AntiMalware
2017-11-28 23:46 . 2017-11-28 23:46 -------- d-----w- c:\users\Petr\AppData\Local\Zemana
2017-11-28 23:44 . 2017-11-28 23:42 24064 ----a-w- c:\windows\zoek-delete.exe
2017-11-28 23:44 . 2017-11-28 23:44 -------- d-----w- c:\users\Petr\AppData\Local\Data aplikacÝ
2017-11-28 23:44 . 2017-11-28 23:45 -------- d-----w- C:\zoek
2017-11-28 01:04 . 2017-11-28 01:04 1313792 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programy\VITSOFT\Vit Registry Fix\zoek.exe
2017-11-28 01:04 . 2017-11-28 01:04 1313792 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VITSOFT\Vit Registry Fix\zoek.exe
2017-11-27 21:45 . 2017-10-30 09:27 13771264 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2017-11-26 21:02 . 2017-11-28 01:10 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-11-26 21:02 . 2017-11-26 21:27 -------- d-----w- c:\programdata\RogueKiller
2017-11-26 20:59 . 2017-11-26 20:59 -------- d-----w- c:\programdata\Sophos
2017-11-26 20:58 . 2017-11-26 20:58 -------- d-----w- c:\program files (x86)\Sophos
2017-11-26 20:44 . 2017-11-26 20:44 26838600 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programy\VITSOFT\Vit Registry Fix\RogueKiller_portable64.exe
2017-11-26 20:44 . 2017-11-26 20:44 26838600 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VITSOFT\Vit Registry Fix\RogueKiller_portable64.exe
2017-11-26 20:42 . 2017-11-26 20:43 1790024 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programy\VITSOFT\Vit Registry Fix\JRT.exe
2017-11-26 20:42 . 2017-11-26 20:43 1790024 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VITSOFT\Vit Registry Fix\JRT.exe
2017-11-26 17:02 . 2017-11-26 17:02 8261584 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programy\VITSOFT\Vit Registry Fix\adwcleaner_7.0.4.0.exe
2017-11-26 17:02 . 2017-11-26 17:02 8261584 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VITSOFT\Vit Registry Fix\adwcleaner_7.0.4.0.exe
2017-11-26 16:39 . 2017-11-01 07:54 77432 ----a-w- c:\windows\system32\drivers\mbae64.sys
2017-11-26 16:38 . 2017-11-26 16:38 448512 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programy\VITSOFT\Vit Registry Fix\TFC.exe
2017-11-26 16:38 . 2017-11-26 16:38 448512 ----a-w- c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VITSOFT\Vit Registry Fix\TFC.exe
2017-11-26 08:45 . 2017-11-26 16:49 -------- d-----w- c:\program files (x86)\7-Zip
2017-11-25 22:42 . 2017-11-25 22:42 -------- d-----w- c:\program files (x86)\Secunia
2017-11-25 21:01 . 2017-11-25 21:01 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2017-11-18 10:49 . 2017-11-18 10:49 -------- d-----w- c:\program files (x86)\AMD
2017-11-18 10:48 . 2017-11-18 10:48 -------- d-----w- c:\program files\Common Files\ATI Technologies
2017-11-18 09:38 . 2017-09-29 09:10 1057976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{127DE711-7649-4B6C-ADEF-99EF32A3805C}\gapaengine.dll
2017-11-16 19:48 . 2017-11-16 19:48 -------- d-----w- c:\program files\Malwarebytes
2017-11-16 19:24 . 2017-11-16 19:24 -------- d-----w- c:\users\Petr\AppData\Local\RadeonInstaller
2017-11-16 19:18 . 2017-11-16 19:40 122848 ----a-w- c:\windows\system32\RtNicProp64.dll
2017-11-16 19:18 . 2017-11-16 19:40 1074792 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2017-11-16 19:16 . 2017-11-16 19:16 3677160 ----a-w- c:\windows\system32\RTSnMg64.cpl
2017-11-16 00:46 . 2017-11-16 00:46 15948200 ----a-w- c:\windows\system32\atidxx64.dll
2017-11-16 00:46 . 2017-11-16 00:46 13141432 ----a-w- c:\windows\SysWow64\atidxx32.dll
2017-11-16 00:46 . 2017-11-16 00:46 9936 ----a-w- c:\windows\system32\detoured.dll
2017-11-16 00:46 . 2017-11-16 00:46 9936 ----a-w- c:\windows\SysWow64\detoured.dll
2017-11-16 00:46 . 2017-11-16 00:46 1931920 ----a-w- c:\windows\system32\aticfx64.dll
2017-11-16 00:46 . 2017-11-16 00:46 195888 ----a-w- c:\windows\system32\atiuxp64.dll
2017-11-16 00:46 . 2017-11-16 00:46 161344 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2017-11-16 00:46 . 2017-11-16 00:46 1541080 ----a-w- c:\windows\SysWow64\aticfx32.dll
2017-11-16 00:44 . 2017-11-16 00:44 405384 ----a-w- c:\windows\system32\atieah64.exe
2017-11-16 00:43 . 2017-11-16 00:43 148360 ----a-w- c:\windows\system32\atisamu64.dll
2017-11-16 00:42 . 2017-11-16 00:42 543624 ----a-w- c:\windows\system32\amdmcl64.dll
2017-11-16 00:42 . 2017-11-16 00:42 373640 ----a-w- c:\windows\SysWow64\amdmcl32.dll
2017-11-16 00:42 . 2017-11-16 00:42 28929416 ----a-w- c:\windows\SysWow64\atioglxx.dll
2017-11-15 10:13 . 2017-10-18 02:34 134376 ----a-w- c:\windows\system32\CompatTelRunner.exe
2017-11-15 10:13 . 2017-10-18 02:30 605184 ----a-w- c:\windows\system32\aeinv.dll
2017-11-15 10:13 . 2017-10-15 22:04 407392 ----a-w- c:\windows\system32\centel.dll
2017-11-15 10:13 . 2017-10-04 13:04 670208 ----a-w- c:\windows\system32\generaltel.dll
2017-11-15 10:13 . 2017-10-04 13:04 603648 ----a-w- c:\windows\system32\devinv.dll
2017-11-15 10:13 . 2017-10-04 13:04 370688 ----a-w- c:\windows\system32\invagent.dll
2017-11-15 10:13 . 2017-10-04 13:04 241664 ----a-w- c:\windows\system32\aepic.dll
2017-11-15 10:13 . 2017-10-04 13:04 2023936 ----a-w- c:\windows\system32\aitstatic.exe
2017-11-15 10:13 . 2017-10-04 13:04 181760 ----a-w- c:\windows\system32\acmigration.dll
2017-11-15 10:13 . 2017-10-04 13:04 1570304 ----a-w- c:\windows\system32\appraiser.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-11-28 23:44 . 2016-08-19 15:31 65536 ----a-w- c:\windows\system32\spu_storage.bin
2017-11-25 22:50 . 2015-08-27 12:42 803328 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2017-11-25 22:50 . 2015-08-27 12:42 144896 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2017-11-20 20:32 . 2015-08-27 12:57 545440 ------w- c:\windows\system32\MpSigStub.exe
2017-11-16 19:40 . 2015-08-27 12:18 118816 ----a-w- c:\windows\system32\RTNUninst64.dll
2017-11-16 19:13 . 2017-10-12 13:08 127017032 -c--a-w- c:\windows\system32\MRT-KB890830.exe
2017-11-16 19:13 . 2015-08-30 11:53 127017032 -c--a-w- c:\windows\system32\MRT.exe
2017-11-16 00:45 . 2017-07-04 22:37 223112 ----a-w- c:\windows\system32\atig6txx.dll
2017-11-16 00:45 . 2017-07-04 22:37 144776 ----a-w- c:\windows\system32\atig6pxx.dll
2017-11-16 00:44 . 2017-04-03 22:22 1454984 ----a-w- c:\windows\system32\atiadlxx.dll
2017-11-16 00:42 . 2017-07-04 22:35 35220872 ----a-w- c:\windows\system32\atio6axx.dll
2017-09-29 09:10 . 2015-08-30 12:20 1057976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2017-09-13 23:20 . 2017-09-13 23:20 798008 ----a-w- c:\windows\SysWow64\vulkan-1-1-0-61-0.dll
2017-09-13 23:20 . 2017-07-19 13:22 798008 ----a-w- c:\windows\SysWow64\vulkan-1.dll
2017-09-13 23:20 . 2017-09-13 23:20 490296 ----a-w- c:\windows\SysWow64\vulkaninfo-1-1-0-61-0.exe
2017-09-13 23:20 . 2017-07-19 13:22 490296 ----a-w- c:\windows\SysWow64\vulkaninfo.exe
2017-09-13 23:19 . 2017-09-13 23:19 927544 ----a-w- c:\windows\system32\vulkan-1-1-0-61-0.dll
2017-09-13 23:19 . 2017-07-19 13:22 927544 ----a-w- c:\windows\system32\vulkan-1.dll
2017-09-13 23:19 . 2017-09-13 23:19 591160 ----a-w- c:\windows\system32\vulkaninfo-1-1-0-61-0.exe
2017-09-13 23:19 . 2017-07-19 13:22 591160 ----a-w- c:\windows\system32\vulkaninfo.exe
2017-09-13 15:33 . 2017-10-11 13:41 631176 ----a-w- c:\windows\system32\winresume.efi
2017-09-13 15:32 . 2017-10-11 13:41 706792 ----a-w- c:\windows\system32\winload.efi
2017-09-13 15:32 . 2017-10-11 13:41 5547752 ----a-w- c:\windows\system32\ntoskrnl.exe
2017-09-13 15:32 . 2017-10-11 13:41 95464 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2017-09-13 15:32 . 2017-10-11 13:41 154856 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2017-09-13 15:31 . 2017-10-11 13:41 1732864 ----a-w- c:\windows\system32\ntdll.dll
2017-09-13 15:28 . 2017-10-11 13:41 448512 ----a-w- c:\windows\system32\wlansec.dll
2017-09-13 15:28 . 2017-10-11 13:41 414208 ----a-w- c:\windows\system32\wlanmsm.dll
2017-09-13 15:28 . 2017-10-11 13:41 886272 ----a-w- c:\windows\system32\wlansvc.dll
2017-09-13 15:28 . 2017-10-11 13:41 118784 ----a-w- c:\windows\system32\wlanhlp.dll
2017-09-13 15:28 . 2017-10-11 13:41 113664 ----a-w- c:\windows\system32\wlanapi.dll
2017-09-13 15:28 . 2017-10-11 13:41 362496 ----a-w- c:\windows\system32\wow64win.dll
2017-09-13 15:28 . 2017-10-11 13:41 215552 ----a-w- c:\windows\system32\winsrv.dll
2017-09-13 15:28 . 2017-10-11 13:41 243712 ----a-w- c:\windows\system32\wow64.dll
2017-09-13 15:28 . 2017-10-11 13:41 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2017-09-13 15:28 . 2017-10-11 13:41 86528 ----a-w- c:\windows\system32\TSpkg.dll
2017-09-13 15:28 . 2017-10-11 13:41 210432 ----a-w- c:\windows\system32\wdigest.dll
2017-09-13 15:28 . 2017-10-11 13:41 503808 ----a-w- c:\windows\system32\srcore.dll
2017-09-13 15:28 . 2017-10-11 13:41 135680 ----a-w- c:\windows\system32\sspicli.dll
2017-09-13 15:28 . 2017-10-11 13:41 50176 ----a-w- c:\windows\system32\srclient.dll
2017-09-13 15:28 . 2017-10-11 13:41 28672 ----a-w- c:\windows\system32\sspisrv.dll
2017-09-13 15:28 . 2017-10-11 13:41 63488 ----a-w- c:\windows\system32\setbcdlocale.dll
2017-09-13 15:28 . 2017-10-11 13:41 1212928 ----a-w- c:\windows\system32\rpcrt4.dll
2017-09-13 15:28 . 2017-10-11 13:41 345600 ----a-w- c:\windows\system32\schannel.dll
2017-09-13 15:28 . 2017-10-11 13:41 190464 ----a-w- c:\windows\system32\rpchttp.dll
2017-09-13 15:28 . 2017-10-11 13:41 28160 ----a-w- c:\windows\system32\secur32.dll
2017-09-13 15:28 . 2017-10-11 13:41 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2017-09-13 15:28 . 2017-10-11 13:41 312320 ----a-w- c:\windows\system32\ncrypt.dll
2017-09-13 15:28 . 2017-10-11 13:41 1068544 ----a-w- c:\windows\system32\msctf.dll
2017-09-13 15:28 . 2017-10-11 13:41 316928 ----a-w- c:\windows\system32\msv1_0.dll
2017-09-13 15:28 . 2017-10-11 13:41 60416 ----a-w- c:\windows\system32\msobjs.dll
2017-09-13 15:28 . 2017-10-11 13:41 146432 ----a-w- c:\windows\system32\msaudite.dll
2017-09-13 15:27 . 2017-10-11 13:41 731648 ----a-w- c:\windows\system32\kerberos.dll
2017-09-13 15:27 . 2017-10-11 13:41 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2017-09-13 15:27 . 2017-10-11 13:41 1163264 ----a-w- c:\windows\system32\kernel32.dll
2017-09-13 15:27 . 2017-10-11 13:41 419840 ----a-w- c:\windows\system32\KernelBase.dll
2017-09-13 15:27 . 2017-10-11 13:41 44032 ----a-w- c:\windows\system32\csrsrv.dll
2017-09-13 15:27 . 2017-10-11 13:41 43520 ----a-w- c:\windows\system32\cryptbase.dll
2017-09-13 15:27 . 2017-10-11 13:41 22016 ----a-w- c:\windows\system32\credssp.dll
2017-09-13 15:27 . 2017-10-11 13:41 463872 ----a-w- c:\windows\system32\certcli.dll
2017-09-13 15:27 . 2017-10-11 13:41 880640 ----a-w- c:\windows\system32\advapi32.dll
2017-09-13 15:27 . 2017-10-11 13:41 123904 ----a-w- c:\windows\system32\bcrypt.dll
2017-09-13 15:27 . 2017-10-11 13:41 59904 ----a-w- c:\windows\system32\appidapi.dll
2017-09-13 15:27 . 2017-10-11 13:41 34816 ----a-w- c:\windows\system32\appidsvc.dll
2017-09-13 15:27 . 2017-10-11 13:41 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 6656 ----a-w- c:\windows\system32\apisetschema.dll
2017-09-13 15:27 . 2017-10-11 13:41 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-09-13 15:27 . 2017-10-11 13:41 690688 ----a-w- c:\windows\system32\adtschema.dll
2017-09-13 15:13 . 2017-10-11 13:41 4001512 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2017-09-13 15:13 . 2017-10-11 13:41 3945704 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2017-09-13 15:10 . 2017-10-11 13:41 1314112 ----a-w- c:\windows\SysWow64\ntdll.dll
2017-09-13 15:09 . 2017-10-11 13:41 666112 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2017-09-13 15:09 . 2017-10-11 13:41 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2017-09-13 15:09 . 2017-10-11 13:41 275456 ----a-w- c:\windows\SysWow64\KernelBase.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x]
R3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus;c:\windows\system32\DRIVERS\dtliteusbbus.sys;c:\windows\SYSNATIVE\DRIVERS\dtliteusbbus.sys [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys;c:\windows\SYSNATIVE\DRIVERS\lv302a64.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys;c:\windows\SYSNATIVE\drivers\LVUSBS64.sys [x]
R3 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R4 WsAppService;Wondershare Application Framework Service;c:\program files (x86)\Wondershare\WAF\2.4.3.225\WsAppService.exe;c:\program files (x86)\Wondershare\WAF\2.4.3.225\WsAppService.exe [x]
S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys;c:\windows\SYSNATIVE\DRIVERS\amdide64.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S1 ZAM;ZAM Helper Driver;c:\windows\System32\drivers\zam64.sys;c:\windows\SYSNATIVE\drivers\zam64.sys [x]
S1 ZAM_Guard;ZAM Guard Driver;c:\windows\System32\drivers\zamguard64.sys;c:\windows\SYSNATIVE\drivers\zamguard64.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 ei2c;ei2c;c:\windows\system32\drivers\ei2c.sys;c:\windows\SYSNATIVE\drivers\ei2c.sys [x]
S2 mi2c;mi2c;c:\windows\system32\drivers\mi2c.sys;c:\windows\SYSNATIVE\drivers\mi2c.sys [x]
S2 ZAMSvc;ZAM Controller Service;c:\program files (x86)\Zemana AntiMalware\ZAM.exe;c:\program files (x86)\Zemana AntiMalware\ZAM.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 KYEKBPRO;IMPERATOR PRO Gaming Keyboard;c:\windows\system32\drivers\KYEKBPRO.sys;c:\windows\SYSNATIVE\drivers\KYEKBPRO.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ZAM
*NewlyCreated* - ZAM_GUARD
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
LocalDriverService REG_MULTI_SZ LDrvSvc
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZAM"="c:\program files (x86)\Zemana AntiMalware\ZAM.exe" [2017-08-09 15775888]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
IE: S10 Autologin
IE: S10 Autotype...
TCP: Interfaces\{9317833D-D4B3-4B9C-8B06-9B224515606B}: NameServer = 94.74.192.252,8.8.8.8
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{056D528D-CE28-4194-9BA3-BA2E9197FF8C} - (no file)
ShellIconOverlayIdentifiers-{05B38830-F4E9-4329-978B-1DD28605D202} - (no file)
ShellIconOverlayIdentifiers-{0596C850-7BDD-4C9D-AFDF-873BE6890637} - (no file)
ShellIconOverlayIdentifiers-{056D528D-CE28-4194-9BA3-BA2E9197FF8C} - (no file)
ShellIconOverlayIdentifiers-{05B38830-F4E9-4329-978B-1DD28605D202} - (no file)
ShellIconOverlayIdentifiers-{0596C850-7BDD-4C9D-AFDF-873BE6890637} - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_27_0_0_187_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_27_0_0_187_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_27_0_0_187_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_27_0_0_187_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_27_0_0_187.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.27"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_27_0_0_187.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_27_0_0_187.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_27_0_0_187.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2017-11-29 01:15:02
ComboFix-quarantined-files.txt 2017-11-29 00:15
.
Před spuštěním: Volných bajtů: 646 074 597 376
Po spuštění: Volných bajtů: 645 473 144 832
.
- - End Of File - - 4E2FED9699600A8F74806163DF575A23
A36C5E4F47E84449FF07ED3517B43A31