Pomalý internet
Napsal: 20 bře 2011 23:39
Chci požadat o pomoc. Zpomalil se mi internet. Nové PC s Windows 7. Připojuji výpis s Combofix. Díky za pomoc
ComboFix 11-03-19.04 - stone 20/03/2011 21:49:34.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1029.18.3071.2201 [GMT 0:00]
Running from: d:\stone\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-02-20 to 2011-03-20 )))))))))))))))))))))))))))))))
.
.
2011-03-20 22:03 . 2011-03-20 22:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-20 20:00 . 2011-03-20 21:04 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-03-20 20:00 . 2011-03-20 20:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-20 19:51 . 2011-03-20 19:51 -------- d-----w- c:\program files\CCleaner
2011-03-20 19:35 . 2011-03-20 19:35 -------- d-----w- c:\program files\TeamViewer
2011-03-19 22:24 . 2011-03-19 22:24 -------- d-----w- c:\windows\Webcam1200
2011-03-19 22:23 . 2011-03-19 22:24 -------- d-----w- c:\program files\Webcam 1200
2011-03-19 22:23 . 2001-11-05 10:50 69632 ----a-w- c:\windows\AMCap.exe
2011-03-19 22:14 . 2011-03-19 22:14 -------- d-----w- c:\program files\Logitech
2011-03-19 22:13 . 1998-10-29 16:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-03-19 22:12 . 2011-03-19 22:16 53248 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\msihook.dll
2011-03-19 22:12 . 2011-03-19 22:16 126976 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\knlwrap.exe
2011-03-19 22:12 . 2001-09-05 04:18 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2011-03-19 22:12 . 2001-09-05 04:18 225280 ------w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
2011-03-19 22:12 . 2001-09-05 04:14 176128 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2011-03-19 22:12 . 2001-09-05 04:13 32768 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2011-03-19 17:33 . 2011-03-19 17:33 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-03-19 16:58 . 2011-03-19 16:58 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-03-19 16:58 . 2011-03-19 16:58 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-03-19 16:58 . 2003-11-10 18:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-03-19 16:58 . 2003-11-10 18:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-03-19 16:58 . 2003-11-10 18:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-03-19 16:58 . 2003-11-10 18:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-03-19 16:58 . 2003-11-10 18:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-03-19 16:57 . 2011-03-19 17:22 -------- d-----w- c:\program files\Common Files\LogiShrd
2011-03-19 16:56 . 2011-03-19 17:22 -------- d-----w- c:\program files\Labtec
2011-03-19 13:26 . 2011-03-19 13:26 -------- d-----w- c:\program files\XnView
2011-03-19 13:20 . 2011-03-19 13:20 -------- d-----w- c:\program files\Common Files\Skype
2011-03-19 13:19 . 2011-03-19 13:20 -------- d-----r- c:\program files\Skype
2011-03-19 13:19 . 2011-03-19 13:19 -------- d-----w- c:\programdata\Skype
2011-03-19 13:04 . 2011-02-23 10:35 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DC67AD17-5EAE-4F48-A13E-6A5E2CC848D7}\mpengine.dll
2011-03-19 12:55 . 2011-03-19 12:56 -------- d-----w- C:\totalcmd
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\UC.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\RAR.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\PKZIP.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\LHA.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\ARJ.PIF
2011-03-19 12:52 . 2011-03-19 13:46 -------- d-----w- c:\users\stone
2011-03-19 12:48 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-03-19 12:48 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-03-19 12:48 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-03-19 12:48 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-03-19 12:48 . 2011-01-13 08:37 51280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-03-19 12:47 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-03-19 12:47 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-03-19 12:47 . 2011-03-19 12:47 -------- d-----w- c:\programdata\Alwil Software
2011-03-19 12:47 . 2011-03-19 12:47 -------- d-----w- c:\program files\Alwil Software
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-03-01 16949128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-03-17 8546848]
"AtherosBtStack"="c:\program files\Atheros\Bluetooth Suite\BtvStack.exe" [2010-05-05 461984]
"AthBtTray"="c:\program files\Atheros\Bluetooth Suite\AthBtTray.exe" [2010-05-05 289952]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-03-30 113296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
.
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\System32\Drivers\AthDfu.sys [2010-03-30 47144]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\Atheros\Ath_CoexAgent.exe [2010-04-29 151552]
S2 AtherosSvc;AtherosSvc;c:\program files\Atheros\Bluetooth Suite\adminservice.exe [2010-05-05 38560]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-01 2296696]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2010-03-30 38440]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2010-04-18 256360]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2010-03-30 28200]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2010-03-30 177704]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2010-04-13 46952]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2010-04-18 143080]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2010-04-21 230760]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-02-24 60544]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-02-24 141568]
S3 nuviocir;Nuvoton W836x7HG CIR Device Driver;c:\windows\system32\DRIVERS\nuviocir_win7_x86.sys [2009-06-19 29696]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-01-28 68200]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
.
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.hal3000.cz
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\users\stone\AppData\Roaming\Mozilla\Firefox\Profiles\0eav7gup.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-03-20 22:18:10
ComboFix-quarantined-files.txt 2011-03-20 22:18
.
Pre-Run: Volnřch bajtu: 115,570,270,208
Post-Run: Volnřch bajtu: 115,480,240,128
.
- - End Of File - - 85E4F034FB8C12AE99DAA808A3E7FAF9
ComboFix 11-03-19.04 - stone 20/03/2011 21:49:34.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1029.18.3071.2201 [GMT 0:00]
Running from: d:\stone\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-02-20 to 2011-03-20 )))))))))))))))))))))))))))))))
.
.
2011-03-20 22:03 . 2011-03-20 22:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-20 20:00 . 2011-03-20 21:04 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-03-20 20:00 . 2011-03-20 20:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-20 19:51 . 2011-03-20 19:51 -------- d-----w- c:\program files\CCleaner
2011-03-20 19:35 . 2011-03-20 19:35 -------- d-----w- c:\program files\TeamViewer
2011-03-19 22:24 . 2011-03-19 22:24 -------- d-----w- c:\windows\Webcam1200
2011-03-19 22:23 . 2011-03-19 22:24 -------- d-----w- c:\program files\Webcam 1200
2011-03-19 22:23 . 2001-11-05 10:50 69632 ----a-w- c:\windows\AMCap.exe
2011-03-19 22:14 . 2011-03-19 22:14 -------- d-----w- c:\program files\Logitech
2011-03-19 22:13 . 1998-10-29 16:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-03-19 22:12 . 2011-03-19 22:16 53248 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\msihook.dll
2011-03-19 22:12 . 2011-03-19 22:16 126976 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\knlwrap.exe
2011-03-19 22:12 . 2001-09-05 04:18 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2011-03-19 22:12 . 2001-09-05 04:18 225280 ------w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
2011-03-19 22:12 . 2001-09-05 04:14 176128 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2011-03-19 22:12 . 2001-09-05 04:13 32768 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2011-03-19 17:33 . 2011-03-19 17:33 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-03-19 16:58 . 2011-03-19 16:58 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-03-19 16:58 . 2011-03-19 16:58 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-03-19 16:58 . 2003-11-10 18:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-03-19 16:58 . 2003-11-10 18:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-03-19 16:58 . 2003-11-10 18:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-03-19 16:58 . 2003-11-10 18:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-03-19 16:58 . 2003-11-10 18:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-03-19 16:57 . 2011-03-19 17:22 -------- d-----w- c:\program files\Common Files\LogiShrd
2011-03-19 16:56 . 2011-03-19 17:22 -------- d-----w- c:\program files\Labtec
2011-03-19 13:26 . 2011-03-19 13:26 -------- d-----w- c:\program files\XnView
2011-03-19 13:20 . 2011-03-19 13:20 -------- d-----w- c:\program files\Common Files\Skype
2011-03-19 13:19 . 2011-03-19 13:20 -------- d-----r- c:\program files\Skype
2011-03-19 13:19 . 2011-03-19 13:19 -------- d-----w- c:\programdata\Skype
2011-03-19 13:04 . 2011-02-23 10:35 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DC67AD17-5EAE-4F48-A13E-6A5E2CC848D7}\mpengine.dll
2011-03-19 12:55 . 2011-03-19 12:56 -------- d-----w- C:\totalcmd
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\UC.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\RAR.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\PKZIP.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\LHA.PIF
2011-03-19 12:55 . 2008-04-22 07:03 545 ----a-w- c:\windows\ARJ.PIF
2011-03-19 12:52 . 2011-03-19 13:46 -------- d-----w- c:\users\stone
2011-03-19 12:48 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-03-19 12:48 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-03-19 12:48 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-03-19 12:48 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-03-19 12:48 . 2011-01-13 08:37 51280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-03-19 12:47 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-03-19 12:47 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-03-19 12:47 . 2011-03-19 12:47 -------- d-----w- c:\programdata\Alwil Software
2011-03-19 12:47 . 2011-03-19 12:47 -------- d-----w- c:\program files\Alwil Software
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-03-01 16949128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-03-17 8546848]
"AtherosBtStack"="c:\program files\Atheros\Bluetooth Suite\BtvStack.exe" [2010-05-05 461984]
"AthBtTray"="c:\program files\Atheros\Bluetooth Suite\AthBtTray.exe" [2010-05-05 289952]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-03-30 113296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
.
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\System32\Drivers\AthDfu.sys [2010-03-30 47144]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\Atheros\Ath_CoexAgent.exe [2010-04-29 151552]
S2 AtherosSvc;AtherosSvc;c:\program files\Atheros\Bluetooth Suite\adminservice.exe [2010-05-05 38560]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-01 2296696]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2010-03-30 38440]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2010-04-18 256360]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2010-03-30 28200]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2010-03-30 177704]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2010-04-13 46952]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2010-04-18 143080]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2010-04-21 230760]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-02-24 60544]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-02-24 141568]
S3 nuviocir;Nuvoton W836x7HG CIR Device Driver;c:\windows\system32\DRIVERS\nuviocir_win7_x86.sys [2009-06-19 29696]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-01-28 68200]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
.
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.hal3000.cz
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\users\stone\AppData\Roaming\Mozilla\Firefox\Profiles\0eav7gup.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-03-20 22:18:10
ComboFix-quarantined-files.txt 2011-03-20 22:18
.
Pre-Run: Volnřch bajtu: 115,570,270,208
Post-Run: Volnřch bajtu: 115,480,240,128
.
- - End Of File - - 85E4F034FB8C12AE99DAA808A3E7FAF9