ComboFix 14-05-19.01 - user 20.05.2014 15:53:11.2.2 - x64
Spuštěný z: c:\users\user\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\user\Desktop\CFScript.txt
.
FILE ::
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3025503433-2825139817-749691780-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3025503433-2825139817-749691780-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateComRegisterShell64.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.24.7\goopdate.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.24.7\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.24.7\psmachine.dll
c:\program files (x86)\Google\Update\1.3.24.7\psmachine_64.dll
c:\program files (x86)\Google\Update\1.3.24.7\psuser.dll
c:\program files (x86)\Google\Update\1.3.24.7\psuser_64.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.24.7\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\34.0.1847.137\34.0.1847.137_34.0.1847.131_chrome_updater.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\users\user\AppData\Local\Facebook\Update
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\FacebookCrashHandler.exe
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdate.exe
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdateHelper.msi
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ar.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bg.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bn.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ca.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_cs.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_da.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_de.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_el.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en-GB.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es-419.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_et.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fa.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fi.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fil.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fr.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_gu.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hi.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hr.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hu.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_id.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_is.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_it.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_iw.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ja.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_kn.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ko.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lt.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lv.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ml.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_mr.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ms.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_nl.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_no.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_or.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pl.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-BR.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-PT.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ro.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ru.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sk.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sl.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sr.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sv.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ta.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_te.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_th.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_tr.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_uk.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ur.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_vi.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-CN.dll
c:\users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-TW.dll
c:\users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-04-20 do 2014-05-20 )))))))))))))))))))))))))))))))
.
.
2014-05-18 19:35 . 2014-05-18 19:35 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-05-18 18:46 . 2014-05-19 15:17 -------- d-----w- c:\windows\ERUNT
2014-05-18 13:56 . 2014-05-20 12:27 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-18 13:56 . 2014-04-03 07:51 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-05-18 13:56 . 2014-04-03 07:51 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-05-18 13:56 . 2014-04-03 07:50 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-05-18 13:56 . 2014-05-18 13:56 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-05-18 13:56 . 2014-05-18 13:56 -------- d-----w- c:\programdata\Malwarebytes
2014-05-18 13:00 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-05-18 12:59 . 2014-05-18 18:26 -------- d-----w- C:\AdwCleaner
2014-05-17 11:28 . 2014-05-19 19:02 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{45759058-C605-4D61-B696-99875D8F308C}\offreg.dll
2014-05-16 14:50 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{45759058-C605-4D61-B696-99875D8F308C}\mpengine.dll
2014-05-14 20:38 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll
2014-05-14 20:38 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-14 20:38 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-14 20:38 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-14 18:11 . 2014-05-14 18:11 17938608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-05-14 18:11 . 2014-03-25 02:43 14175744 ----a-w- c:\windows\system32\shell32.dll
2014-05-14 18:11 . 2014-05-09 06:14 477184 ----a-w- c:\windows\system32\aepdu.dll
2014-05-14 18:11 . 2014-05-09 06:11 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-05-11 12:54 . 2014-05-15 16:04 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2014-05-06 14:32 . 2014-05-14 20:42 -------- d-s---w- c:\windows\system32\CompatTel
2014-05-03 17:02 . 2014-05-03 17:02 -------- d-----w- c:\users\user\AppData\Roaming\Image-Line
2014-05-03 17:02 . 2014-05-03 17:02 -------- d-----w- c:\program files\Image-Line
2014-05-03 17:01 . 2014-05-03 17:01 -------- d-----w- c:\users\user\AppData\Roaming\FlowStone
2014-05-03 17:01 . 2014-05-17 14:02 -------- d-----w- c:\program files (x86)\DSPRobotics
2014-05-03 16:50 . 2014-05-03 17:02 -------- d-----w- c:\program files (x86)\Image-Line
2014-04-22 14:42 . 2014-03-06 08:59 66048 ----a-w- c:\windows\system32\iesetup.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-15 16:04 . 2013-11-11 14:19 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-05-15 16:04 . 2012-09-12 15:09 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-05-15 16:04 . 2013-12-18 14:02 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-05-14 20:34 . 2012-09-14 10:53 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-05-14 18:12 . 2012-05-13 21:56 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-14 18:12 . 2012-05-13 21:56 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-20 09:33 . 2014-04-20 09:33 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-04-20 09:33 . 2013-03-02 15:10 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-20 09:33 . 2013-03-02 15:10 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-20 09:33 . 2012-09-12 15:09 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-20 09:33 . 2012-09-12 15:09 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-20 09:33 . 2012-09-12 15:09 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-04-20 09:33 . 2014-04-20 09:33 43152 ----a-w- c:\windows\avastSS.scr
2014-04-17 03:31 . 2014-05-20 14:07 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C80F1CB0-0DA4-4C5C-85C0-F1E008999441}\mpengine.dll
2014-04-12 10:14 . 2013-10-22 16:45 578256 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2014-03-31 07:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-04 09:44 . 2014-04-09 13:44 243712 ----a-w- c:\windows\system32\wow64.dll
2014-03-04 09:44 . 2014-04-09 13:44 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-03-04 09:44 . 2014-04-09 13:44 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2014-03-04 09:44 . 2014-05-14 18:10 340992 ----a-w- c:\windows\system32\schannel.dll
2014-03-04 09:44 . 2014-04-09 13:44 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2014-03-04 09:44 . 2014-04-09 13:44 1163264 ----a-w- c:\windows\system32\kernel32.dll
2014-03-04 09:17 . 2014-05-14 18:10 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2014-03-04 09:17 . 2014-04-09 13:44 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2014-03-04 09:17 . 2014-04-09 13:44 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-03-04 09:16 . 2014-04-09 13:44 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2014-03-04 09:16 . 2014-04-09 13:43 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2014-03-04 08:09 . 2014-04-09 13:43 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2014-03-04 08:09 . 2014-04-09 13:43 2048 ----a-w- c:\windows\SysWow64\user.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-10-22 16:53 222712 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-10-22 16:53 222712 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-10-22 16:53 222712 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2011-04-02 80840]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-05 291608]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-20 3873704]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
R3 RtkBtFilter;Realtek Bluetooth Filter Driver;c:\windows\system32\DRIVERS\RtkBtfilter.sys;c:\windows\SYSNATIVE\DRIVERS\RtkBtfilter.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bbus.sys [x]
R3 TDEIO;TDEIO;c:\windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys;c:\windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys;c:\windows\SYSNATIVE\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys;c:\windows\SYSNATIVE\DRIVERS\NBVolUp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys;c:\windows\SYSNATIVE\DRIVERS\tos_sps64.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 ClickToRunSvc;Služba Microsoft Office ClickToRun;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [x]
S2 GFNEXSrv;GFNEX Service;c:\windows\System32\GFNEXSrv.exe;c:\windows\SYSNATIVE\GFNEXSrv.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-16 15:14 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.137\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-05-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-13 18:13]
.
2014-05-20 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
2014-05-19 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-10-22 16:53 261624 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-10-22 16:53 261624 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-10-22 16:53 261624 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-04-12 10:15 2333400 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-04-12 10:15 2333400 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-04-12 10:15 2333400 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-04-20 09:33 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-03-16 12459112]
"SRS Premium Sound HD"="c:\program files\SRS Labs\SRS Control Panel\SRSPanel_64.exe" [2012-03-22 2165120]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2011-11-26 710560]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2011-02-10 1546720]
"Toshiba Registration"="c:\program files\TOSHIBA\Registration\ToshibaReminder.exe" [2012-05-13 150992]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-05-10 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-05-10 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-05-10 440088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
hxxp://www.google.commLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 213.46.172.37 213.46.172.46
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\209jvf9y.default\
FF - prefs.js: browser.startup.homepage -
hxxps://www.google.cz/.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
c:\program files (x86)\Canon\IJPLM\IJPLMSVC.EXE
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\program files\Microsoft Office 15\Root\Office15\MsoSync.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-05-20 16:13:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-05-20 14:12
ComboFix2.txt 2014-05-19 19:13
.
Před spuštěním: Volných bajtů: 155 402 584 064
Po spuštění: Volných bajtů: 154 929 852 416
.
- - End Of File - - 8FC1A2D53E5AF416867B5419C6E23F69