ComboFix 13-08-25.01 - ZiGi 25.08.2013 15:39:10.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.8191.6267 [GMT 2:00]
Spuštěný z: c:\users\ZiGi\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\ZiGi\AppData\Roaming\dclogs
c:\users\ZiGi\AppData\Roaming\dclogs\2013-08-23-6.dc
c:\users\ZiGi\AppData\Roaming\dclogs\2013-08-24-7.dc
c:\users\ZiGi\AppData\Roaming\dclogs\2013-08-25-1.dc
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-25 do 2013-08-25 )))))))))))))))))))))))))))))))
.
.
2013-08-25 13:45 . 2013-08-25 13:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-25 13:27 . 2013-08-25 13:27 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{984CC241-8AB5-496B-84C2-ED91EFDE0A3B}\offreg.dll
2013-08-25 13:20 . 2013-08-25 13:20 -------- d-----w- c:\windows\ERUNT
2013-08-25 13:10 . 2013-08-25 13:13 -------- d-----w- C:\AdwCleaner
2013-08-25 13:03 . 2013-08-25 13:03 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-25 13:03 . 2013-08-25 13:03 -------- d-----w- c:\programdata\Malwarebytes
2013-08-25 13:03 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-25 11:29 . 2013-08-25 11:29 -------- d-----w- c:\program files (x86)\Trend Micro
2013-08-23 08:34 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{984CC241-8AB5-496B-84C2-ED91EFDE0A3B}\mpengine.dll
2013-08-22 22:04 . 2013-08-21 21:44 2601752 ----a-w- c:\windows\SysWow64\pbsvc_moh.exe
2013-08-22 11:43 . 2013-08-24 18:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-08-22 11:42 . 2013-08-22 11:42 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2013-08-22 11:41 . 2013-08-22 11:41 -------- d-----w- c:\programdata\EA Core
2013-08-22 11:41 . 2013-08-22 12:58 -------- d-----w- c:\programdata\EA Logs
2013-08-22 07:40 . 2013-08-22 07:40 -------- d-sh--w- c:\programdata\DSS
2013-08-22 07:37 . 2013-08-22 07:37 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
2013-08-22 02:46 . 2013-08-22 02:46 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2013-08-22 02:46 . 2013-08-24 18:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-08-22 02:46 . 2013-08-24 18:37 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-08-21 21:29 . 2013-08-21 21:57 -------- d-----w- c:\program files (x86)\Origin Games
2013-08-21 21:16 . 2013-08-22 11:41 -------- d-----w- c:\programdata\Electronic Arts
2013-08-21 21:16 . 2013-08-21 21:57 -------- d-----w- c:\programdata\Origin
2013-08-21 21:15 . 2013-08-25 13:15 -------- d-----w- c:\program files (x86)\Origin
2013-08-18 18:01 . 2013-08-18 18:01 -------- d-----w- c:\program files (x86)\dumps
2013-08-18 18:01 . 2013-08-18 18:01 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-08-18 18:01 . 2013-08-25 13:16 -------- d-----w- c:\program files (x86)\Steam
2013-08-14 23:08 . 2013-08-14 23:08 -------- d-----w- C:\50b7415be8e6d6c681
2013-08-12 11:02 . 2009-09-04 15:44 517960 ----a-w- c:\windows\system32\XAudio2_5.dll
2013-08-11 16:46 . 2013-08-11 16:46 -------- d-----w- c:\program files (x86)\Deep Silver
2013-08-11 16:34 . 2013-08-11 16:34 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-08-11 16:34 . 2013-08-11 16:34 -------- d-----w- c:\windows\SysWow64\AGEIA
2013-08-11 16:34 . 2013-08-22 07:37 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-11 15:50 . 2006-03-31 10:41 3927248 ----a-w- c:\windows\system32\d3dx9_30.dll
2013-08-11 15:44 . 2013-08-19 17:02 -------- d-----w- c:\program files (x86)\FlatOut2
2013-08-11 14:08 . 2013-08-11 14:08 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-11 14:08 . 2013-08-11 14:08 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-08-11 14:07 . 2013-08-11 14:09 -------- d-----w- c:\programdata\DAEMON Tools Lite
2013-08-11 11:13 . 2013-08-19 17:06 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-11 11:13 . 2013-08-19 17:06 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-11 11:13 . 2013-08-11 11:13 -------- d-----w- c:\windows\system32\Macromed
2013-08-09 12:45 . 2013-08-09 12:45 -------- d-----w- c:\windows\Sun
2013-08-09 12:25 . 2013-08-09 12:25 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2013-08-08 14:27 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-08-08 14:27 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-08 09:10 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-08-08 09:10 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-08-08 08:43 . 2013-08-08 08:43 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 18:13 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-08-07 10:04 . 2013-08-07 10:04 -------- d-----w- c:\windows\SysWow64\Macromed
2013-08-07 09:19 . 2013-08-07 09:19 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-08-07 09:18 . 2013-08-07 09:18 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2013-08-07 08:13 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-08-07 08:13 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-08-07 08:12 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-08-07 08:12 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-08-07 08:12 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-08-07 08:12 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-08-07 08:11 . 2013-08-07 08:11 -------- d-----w- c:\program files (x86)\Microsoft.NET
2013-08-07 08:04 . 2013-08-07 08:04 -------- d-----w- c:\windows\SysWow64\Wat
2013-08-07 08:04 . 2013-08-07 08:04 -------- d-----w- c:\windows\system32\Wat
2013-08-07 05:58 . 2013-08-06 20:04 -------- d-----w- c:\windows\Panther
2013-08-06 23:40 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-08-06 23:40 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-08-06 23:40 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2013-08-06 23:40 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-08-06 23:38 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-08-06 23:35 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2013-08-06 23:35 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2013-08-06 23:35 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-08-06 23:35 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-08-06 23:35 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2013-08-06 23:35 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2013-08-06 23:34 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-08-06 23:34 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-08-06 23:34 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-08-06 23:34 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-08-06 23:34 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-08-06 23:34 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-08-06 23:34 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-08-06 23:33 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-08-06 23:33 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-08-06 23:33 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-08-06 23:33 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-08-06 23:33 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-08-06 22:55 . 2013-08-06 23:02 -------- d-----w- c:\program files (x86)\Counter-Strike Source
2013-08-06 22:51 . 2011-05-10 09:41 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2013-08-06 22:51 . 2011-05-10 09:41 174184 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2013-08-06 22:51 . 2011-05-10 09:41 1426536 ----a-w- c:\windows\system32\nvhdagenco642040.dll
2013-08-06 22:51 . 2013-08-07 09:19 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2013-08-06 22:14 . 2011-08-03 11:50 1453160 ----a-w- c:\windows\system32\nvgenco64.dll
2013-08-06 22:12 . 2011-08-03 11:50 67176 ----a-w- c:\windows\system32\OpenCL.dll
2013-08-06 22:12 . 2011-08-03 11:50 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-08-06 21:43 . 2013-08-06 21:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-08-06 21:43 . 2013-08-06 21:43 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-08-06 21:43 . 2013-08-06 21:43 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-08-06 21:43 . 2013-08-06 21:43 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-06 21:43 . 2013-08-06 21:43 -------- d-----w- c:\program files (x86)\Java
2013-08-06 21:10 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2013-08-06 21:10 . 2011-06-16 05:49 199680 ----a-w- c:\windows\system32\xmllite.dll
2013-08-06 21:08 . 2013-05-27 05:50 1011712 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-08-06 21:07 . 2012-11-22 05:44 800768 ----a-w- c:\windows\system32\usp10.dll
2013-08-06 21:07 . 2012-11-22 04:45 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2013-08-06 21:07 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2013-08-06 21:07 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2013-08-06 21:07 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2013-08-06 21:07 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2013-08-06 21:07 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2013-08-06 21:01 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2013-08-06 21:00 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2013-08-06 20:54 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2013-08-06 20:54 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\cs
2013-08-06 20:45 . 2013-08-08 17:23 -------- d-----w- c:\windows\SysWow64\wbem\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\XPSViewer
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\drivers\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\system32\cs
2013-08-06 20:45 . 2013-08-07 08:04 -------- d-----w- c:\windows\system32\drivers\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\system32\drivers\UMDF\cs-CZ
2013-08-06 20:45 . 2013-08-08 17:23 -------- d-----w- c:\windows\system32\wbem\cs-CZ
2013-08-06 20:42 . 2009-07-13 17:04 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
2013-08-06 20:28 . 2013-08-15 09:39 -------- d-----w- c:\users\UpdatusUser
2013-08-06 20:28 . 2013-08-25 13:14 -------- d-----w- c:\programdata\NVIDIA
2013-08-06 20:27 . 2013-01-18 15:00 6390048 ----a-w- c:\windows\system32\nvcpl.dll
2013-08-06 20:27 . 2013-01-18 15:00 3460896 ----a-w- c:\windows\system32\nvsvc64.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-10 10:08 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2013-08-10 10:08 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2013-08-10 10:08 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2013-08-10 10:08 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2013-08-10 10:08 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2013-07-09 04:45 . 2013-08-14 13:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2013-08-10 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2013-08-10 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-07-25 20684656]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-07-26 1807272]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2013-08-21 3549528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=""
"UpdatesDisableNotify"=""
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;tsusbhub [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-21 08:12 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-11 17:06]
.
2013-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 20:06]
.
2013-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06 20:06]
.
.
--------- X64 Entries -----------
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.0.254
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_moh.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-08-25 15:47:53
ComboFix-quarantined-files.txt 2013-08-25 13:47
.
Před spuštěním: Volných bajtů: 905 306 345 472
Po spuštění: Volných bajtů: 907 251 924 992
.
- - End Of File - - 655D14D55E21AB36E92CBA35CED68375
A36C5E4F47E84449FF07ED3517B43A31
Klávesnice píše dva háčky za sebou
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Klávesnice píše dva háčky za sebou
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upus.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
Driver::
SkypeUpdate
Folder::
c:\program files (x86)\Skype\Updater
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upus.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Klávesnice píše dva háčky za sebou
Ještě něco ? :)
Re: Klávesnice píše dva háčky za sebou
ComboFix 13-08-25.01 - ZiGi 25.08.2013 16:18:10.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.8191.5804 [GMT 2:00]
Spuštěný z: c:\users\ZiGi\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\ZiGi\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-25 do 2013-08-25 )))))))))))))))))))))))))))))))
.
.
2013-08-25 14:20 . 2013-08-25 14:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-25 13:20 . 2013-08-25 13:20 -------- d-----w- c:\windows\ERUNT
2013-08-25 13:10 . 2013-08-25 13:13 -------- d-----w- C:\AdwCleaner
2013-08-25 13:03 . 2013-08-25 13:03 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-25 13:03 . 2013-08-25 13:03 -------- d-----w- c:\programdata\Malwarebytes
2013-08-25 13:03 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-25 11:29 . 2013-08-25 11:29 -------- d-----w- c:\program files (x86)\Trend Micro
2013-08-23 08:34 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{984CC241-8AB5-496B-84C2-ED91EFDE0A3B}\mpengine.dll
2013-08-22 22:04 . 2013-08-21 21:44 2601752 ----a-w- c:\windows\SysWow64\pbsvc_moh.exe
2013-08-22 11:43 . 2013-08-24 18:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-08-22 11:42 . 2013-08-22 11:42 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2013-08-22 11:41 . 2013-08-22 11:41 -------- d-----w- c:\programdata\EA Core
2013-08-22 11:41 . 2013-08-22 12:58 -------- d-----w- c:\programdata\EA Logs
2013-08-22 07:40 . 2013-08-22 07:40 -------- d-sh--w- c:\programdata\DSS
2013-08-22 07:37 . 2013-08-22 07:37 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
2013-08-22 02:46 . 2013-08-22 02:46 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2013-08-22 02:46 . 2013-08-24 18:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-08-22 02:46 . 2013-08-24 18:37 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-08-21 21:29 . 2013-08-21 21:57 -------- d-----w- c:\program files (x86)\Origin Games
2013-08-21 21:16 . 2013-08-22 11:41 -------- d-----w- c:\programdata\Electronic Arts
2013-08-21 21:16 . 2013-08-21 21:57 -------- d-----w- c:\programdata\Origin
2013-08-21 21:15 . 2013-08-25 13:15 -------- d-----w- c:\program files (x86)\Origin
2013-08-18 18:01 . 2013-08-18 18:01 -------- d-----w- c:\program files (x86)\dumps
2013-08-18 18:01 . 2013-08-18 18:01 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-08-18 18:01 . 2013-08-25 13:16 -------- d-----w- c:\program files (x86)\Steam
2013-08-14 23:08 . 2013-08-14 23:08 -------- d-----w- C:\50b7415be8e6d6c681
2013-08-12 11:02 . 2009-09-04 15:44 517960 ----a-w- c:\windows\system32\XAudio2_5.dll
2013-08-11 16:46 . 2013-08-11 16:46 -------- d-----w- c:\program files (x86)\Deep Silver
2013-08-11 16:34 . 2013-08-11 16:34 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-08-11 16:34 . 2013-08-11 16:34 -------- d-----w- c:\windows\SysWow64\AGEIA
2013-08-11 16:34 . 2013-08-22 07:37 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-11 15:50 . 2006-03-31 10:41 3927248 ----a-w- c:\windows\system32\d3dx9_30.dll
2013-08-11 15:44 . 2013-08-19 17:02 -------- d-----w- c:\program files (x86)\FlatOut2
2013-08-11 14:08 . 2013-08-11 14:08 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-11 14:08 . 2013-08-11 14:08 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-08-11 14:07 . 2013-08-11 14:09 -------- d-----w- c:\programdata\DAEMON Tools Lite
2013-08-11 11:13 . 2013-08-19 17:06 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-11 11:13 . 2013-08-19 17:06 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-11 11:13 . 2013-08-11 11:13 -------- d-----w- c:\windows\system32\Macromed
2013-08-09 12:45 . 2013-08-09 12:45 -------- d-----w- c:\windows\Sun
2013-08-09 12:25 . 2013-08-09 12:25 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2013-08-08 14:27 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-08-08 14:27 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-08 09:10 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-08-08 09:10 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-08-08 08:43 . 2013-08-08 08:43 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 18:13 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-08-07 10:04 . 2013-08-07 10:04 -------- d-----w- c:\windows\SysWow64\Macromed
2013-08-07 09:19 . 2013-08-07 09:19 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-08-07 09:18 . 2013-08-07 09:18 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2013-08-07 08:13 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-08-07 08:13 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-08-07 08:12 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-08-07 08:12 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-08-07 08:12 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-08-07 08:12 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-08-07 08:11 . 2013-08-07 08:11 -------- d-----w- c:\program files (x86)\Microsoft.NET
2013-08-07 08:04 . 2013-08-07 08:04 -------- d-----w- c:\windows\SysWow64\Wat
2013-08-07 08:04 . 2013-08-07 08:04 -------- d-----w- c:\windows\system32\Wat
2013-08-07 05:58 . 2013-08-06 20:04 -------- d-----w- c:\windows\Panther
2013-08-06 23:40 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-08-06 23:40 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-08-06 23:40 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2013-08-06 23:40 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-08-06 23:38 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-08-06 23:35 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2013-08-06 23:35 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2013-08-06 23:35 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-08-06 23:35 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-08-06 23:35 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2013-08-06 23:35 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2013-08-06 23:34 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-08-06 23:34 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-08-06 23:34 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-08-06 23:34 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-08-06 23:34 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-08-06 23:34 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-08-06 23:34 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-08-06 23:33 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-08-06 23:33 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-08-06 23:33 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-08-06 23:33 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-08-06 23:33 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-08-06 22:55 . 2013-08-06 23:02 -------- d-----w- c:\program files (x86)\Counter-Strike Source
2013-08-06 22:51 . 2011-05-10 09:41 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2013-08-06 22:51 . 2011-05-10 09:41 174184 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2013-08-06 22:51 . 2011-05-10 09:41 1426536 ----a-w- c:\windows\system32\nvhdagenco642040.dll
2013-08-06 22:51 . 2013-08-07 09:19 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2013-08-06 22:14 . 2011-08-03 11:50 1453160 ----a-w- c:\windows\system32\nvgenco64.dll
2013-08-06 22:12 . 2011-08-03 11:50 67176 ----a-w- c:\windows\system32\OpenCL.dll
2013-08-06 22:12 . 2011-08-03 11:50 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-08-06 21:43 . 2013-08-06 21:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-08-06 21:43 . 2013-08-06 21:43 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-08-06 21:43 . 2013-08-06 21:43 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-08-06 21:43 . 2013-08-06 21:43 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-06 21:43 . 2013-08-06 21:43 -------- d-----w- c:\program files (x86)\Java
2013-08-06 21:10 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2013-08-06 21:10 . 2011-06-16 05:49 199680 ----a-w- c:\windows\system32\xmllite.dll
2013-08-06 21:08 . 2013-05-27 05:50 1011712 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-08-06 21:07 . 2012-11-22 05:44 800768 ----a-w- c:\windows\system32\usp10.dll
2013-08-06 21:07 . 2012-11-22 04:45 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2013-08-06 21:07 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2013-08-06 21:07 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2013-08-06 21:07 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2013-08-06 21:07 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2013-08-06 21:07 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2013-08-06 21:01 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2013-08-06 21:00 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2013-08-06 20:54 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2013-08-06 20:54 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\cs
2013-08-06 20:45 . 2013-08-08 17:23 -------- d-----w- c:\windows\SysWow64\wbem\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\XPSViewer
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\drivers\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\system32\cs
2013-08-06 20:45 . 2013-08-07 08:04 -------- d-----w- c:\windows\system32\drivers\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\system32\drivers\UMDF\cs-CZ
2013-08-06 20:45 . 2013-08-08 17:23 -------- d-----w- c:\windows\system32\wbem\cs-CZ
2013-08-06 20:42 . 2009-07-13 17:04 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
2013-08-06 20:28 . 2013-08-15 09:39 -------- d-----w- c:\users\UpdatusUser
2013-08-06 20:28 . 2013-08-25 14:22 -------- d-----w- c:\programdata\NVIDIA
2013-08-06 20:27 . 2013-01-18 15:00 6390048 ----a-w- c:\windows\system32\nvcpl.dll
2013-08-06 20:27 . 2013-01-18 15:00 3460896 ----a-w- c:\windows\system32\nvsvc64.dll
2013-08-06 20:27 . 2013-01-18 15:00 884512 ----a-w- c:\windows\system32\nvvsvc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-10 10:08 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2013-08-10 10:08 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2013-08-10 10:08 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2013-08-10 10:08 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2013-08-10 10:08 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2013-07-09 04:45 . 2013-08-14 13:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2013-08-10 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2013-08-10 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-07-25 20684656]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-07-26 1807272]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2013-08-21 3549528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=""
"UpdatesDisableNotify"=""
.
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;tsusbhub [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-21 08:12 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-11 17:06]
.
.
--------- X64 Entries -----------
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_moh.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-08-25 16:27:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-08-25 14:27
ComboFix2.txt 2013-08-25 13:47
.
Před spuštěním: Volných bajtů: 907 068 506 112
Po spuštění: Volných bajtů: 906 860 916 736
.
- - End Of File - - 720E4BDCBF656BC0CE812EAB77652C53
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.8191.5804 [GMT 2:00]
Spuštěný z: c:\users\ZiGi\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\ZiGi\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-25 do 2013-08-25 )))))))))))))))))))))))))))))))
.
.
2013-08-25 14:20 . 2013-08-25 14:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-25 13:20 . 2013-08-25 13:20 -------- d-----w- c:\windows\ERUNT
2013-08-25 13:10 . 2013-08-25 13:13 -------- d-----w- C:\AdwCleaner
2013-08-25 13:03 . 2013-08-25 13:03 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-25 13:03 . 2013-08-25 13:03 -------- d-----w- c:\programdata\Malwarebytes
2013-08-25 13:03 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-25 11:29 . 2013-08-25 11:29 -------- d-----w- c:\program files (x86)\Trend Micro
2013-08-23 08:34 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{984CC241-8AB5-496B-84C2-ED91EFDE0A3B}\mpengine.dll
2013-08-22 22:04 . 2013-08-21 21:44 2601752 ----a-w- c:\windows\SysWow64\pbsvc_moh.exe
2013-08-22 11:43 . 2013-08-24 18:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-08-22 11:42 . 2013-08-22 11:42 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2013-08-22 11:41 . 2013-08-22 11:41 -------- d-----w- c:\programdata\EA Core
2013-08-22 11:41 . 2013-08-22 12:58 -------- d-----w- c:\programdata\EA Logs
2013-08-22 07:40 . 2013-08-22 07:40 -------- d-sh--w- c:\programdata\DSS
2013-08-22 07:37 . 2013-08-22 07:37 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
2013-08-22 02:46 . 2013-08-22 02:46 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2013-08-22 02:46 . 2013-08-24 18:37 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-08-22 02:46 . 2013-08-24 18:37 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-08-21 21:29 . 2013-08-21 21:57 -------- d-----w- c:\program files (x86)\Origin Games
2013-08-21 21:16 . 2013-08-22 11:41 -------- d-----w- c:\programdata\Electronic Arts
2013-08-21 21:16 . 2013-08-21 21:57 -------- d-----w- c:\programdata\Origin
2013-08-21 21:15 . 2013-08-25 13:15 -------- d-----w- c:\program files (x86)\Origin
2013-08-18 18:01 . 2013-08-18 18:01 -------- d-----w- c:\program files (x86)\dumps
2013-08-18 18:01 . 2013-08-18 18:01 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-08-18 18:01 . 2013-08-25 13:16 -------- d-----w- c:\program files (x86)\Steam
2013-08-14 23:08 . 2013-08-14 23:08 -------- d-----w- C:\50b7415be8e6d6c681
2013-08-12 11:02 . 2009-09-04 15:44 517960 ----a-w- c:\windows\system32\XAudio2_5.dll
2013-08-11 16:46 . 2013-08-11 16:46 -------- d-----w- c:\program files (x86)\Deep Silver
2013-08-11 16:34 . 2013-08-11 16:34 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-08-11 16:34 . 2013-08-11 16:34 -------- d-----w- c:\windows\SysWow64\AGEIA
2013-08-11 16:34 . 2013-08-22 07:37 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-11 15:50 . 2006-03-31 10:41 3927248 ----a-w- c:\windows\system32\d3dx9_30.dll
2013-08-11 15:44 . 2013-08-19 17:02 -------- d-----w- c:\program files (x86)\FlatOut2
2013-08-11 14:08 . 2013-08-11 14:08 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-08-11 14:08 . 2013-08-11 14:08 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-08-11 14:07 . 2013-08-11 14:09 -------- d-----w- c:\programdata\DAEMON Tools Lite
2013-08-11 11:13 . 2013-08-19 17:06 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-11 11:13 . 2013-08-19 17:06 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-11 11:13 . 2013-08-11 11:13 -------- d-----w- c:\windows\system32\Macromed
2013-08-09 12:45 . 2013-08-09 12:45 -------- d-----w- c:\windows\Sun
2013-08-09 12:25 . 2013-08-09 12:25 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2013-08-08 14:27 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-08-08 14:27 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-08 09:10 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-08-08 09:10 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-08-08 08:43 . 2013-08-08 08:43 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-07 18:13 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-08-07 10:04 . 2013-08-07 10:04 -------- d-----w- c:\windows\SysWow64\Macromed
2013-08-07 09:19 . 2013-08-07 09:19 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-08-07 09:18 . 2013-08-07 09:18 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2013-08-07 08:13 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-08-07 08:13 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-08-07 08:12 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-08-07 08:12 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-08-07 08:12 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-08-07 08:12 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-08-07 08:11 . 2013-08-07 08:11 -------- d-----w- c:\program files (x86)\Microsoft.NET
2013-08-07 08:04 . 2013-08-07 08:04 -------- d-----w- c:\windows\SysWow64\Wat
2013-08-07 08:04 . 2013-08-07 08:04 -------- d-----w- c:\windows\system32\Wat
2013-08-07 05:58 . 2013-08-06 20:04 -------- d-----w- c:\windows\Panther
2013-08-06 23:40 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-08-06 23:40 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-08-06 23:40 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2013-08-06 23:40 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-08-06 23:38 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-08-06 23:35 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2013-08-06 23:35 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2013-08-06 23:35 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-08-06 23:35 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-08-06 23:35 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2013-08-06 23:35 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2013-08-06 23:34 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-08-06 23:34 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-08-06 23:34 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-08-06 23:34 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-08-06 23:34 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-08-06 23:34 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-08-06 23:34 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-08-06 23:33 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-08-06 23:33 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-08-06 23:33 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-08-06 23:33 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-08-06 23:33 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-08-06 22:55 . 2013-08-06 23:02 -------- d-----w- c:\program files (x86)\Counter-Strike Source
2013-08-06 22:51 . 2011-05-10 09:41 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2013-08-06 22:51 . 2011-05-10 09:41 174184 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2013-08-06 22:51 . 2011-05-10 09:41 1426536 ----a-w- c:\windows\system32\nvhdagenco642040.dll
2013-08-06 22:51 . 2013-08-07 09:19 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2013-08-06 22:14 . 2011-08-03 11:50 1453160 ----a-w- c:\windows\system32\nvgenco64.dll
2013-08-06 22:12 . 2011-08-03 11:50 67176 ----a-w- c:\windows\system32\OpenCL.dll
2013-08-06 22:12 . 2011-08-03 11:50 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-08-06 21:43 . 2013-08-06 21:43 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-08-06 21:43 . 2013-08-06 21:43 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-08-06 21:43 . 2013-08-06 21:43 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-08-06 21:43 . 2013-08-06 21:43 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-06 21:43 . 2013-08-06 21:43 -------- d-----w- c:\program files (x86)\Java
2013-08-06 21:10 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2013-08-06 21:10 . 2011-06-16 05:49 199680 ----a-w- c:\windows\system32\xmllite.dll
2013-08-06 21:08 . 2013-05-27 05:50 1011712 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-08-06 21:07 . 2012-11-22 05:44 800768 ----a-w- c:\windows\system32\usp10.dll
2013-08-06 21:07 . 2012-11-22 04:45 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2013-08-06 21:07 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2013-08-06 21:07 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2013-08-06 21:07 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2013-08-06 21:07 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2013-08-06 21:07 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2013-08-06 21:01 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2013-08-06 21:00 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2013-08-06 20:54 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2013-08-06 20:54 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\cs
2013-08-06 20:45 . 2013-08-08 17:23 -------- d-----w- c:\windows\SysWow64\wbem\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\XPSViewer
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\SysWow64\drivers\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\system32\cs
2013-08-06 20:45 . 2013-08-07 08:04 -------- d-----w- c:\windows\system32\drivers\cs-CZ
2013-08-06 20:45 . 2013-08-06 20:45 -------- d-----w- c:\windows\system32\drivers\UMDF\cs-CZ
2013-08-06 20:45 . 2013-08-08 17:23 -------- d-----w- c:\windows\system32\wbem\cs-CZ
2013-08-06 20:42 . 2009-07-13 17:04 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
2013-08-06 20:28 . 2013-08-15 09:39 -------- d-----w- c:\users\UpdatusUser
2013-08-06 20:28 . 2013-08-25 14:22 -------- d-----w- c:\programdata\NVIDIA
2013-08-06 20:27 . 2013-01-18 15:00 6390048 ----a-w- c:\windows\system32\nvcpl.dll
2013-08-06 20:27 . 2013-01-18 15:00 3460896 ----a-w- c:\windows\system32\nvsvc64.dll
2013-08-06 20:27 . 2013-01-18 15:00 884512 ----a-w- c:\windows\system32\nvvsvc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-10 10:08 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2013-08-10 10:08 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2013-08-10 10:08 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2013-08-10 10:08 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2013-08-10 10:08 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2013-07-09 04:45 . 2013-08-14 13:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2013-08-10 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2013-08-10 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-07-25 20684656]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-07-26 1807272]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2013-08-21 3549528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=""
"UpdatesDisableNotify"=""
.
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;tsusbhub [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-21 08:12 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-11 17:06]
.
.
--------- X64 Entries -----------
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_moh.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-08-25 16:27:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-08-25 14:27
ComboFix2.txt 2013-08-25 13:47
.
Před spuštěním: Volných bajtů: 907 068 506 112
Po spuštění: Volných bajtů: 906 860 916 736
.
- - End Of File - - 720E4BDCBF656BC0CE812EAB77652C53
A36C5E4F47E84449FF07ED3517B43A31
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Klávesnice píše dva háčky za sebou
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
+ Nový log z HJT
Jak se chová PC?
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
+ Nový log z HJT
Jak se chová PC?
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Klávesnice píše dva háčky za sebou
čau, klávesnice mi píše dva háčky i dvě čárky a tady přikládám scan z roguekiller. díky za pomoc
RogueKiller V9.2.10.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7600 ) 32 bits version
Spuštěno v : Normální režim
Uživatel : Jeleni [Práva správce]
Mód : Kontrola -- Datum : 09/12/2014 16:48:08
¤¤¤ Škodlivé procesy: : 2 ¤¤¤
[Suspicious.Path] WinDLL.exe -- C:\Users\Jeleni\AppData\Roaming\WinDLL.exe[-] -> SMAZÁNO [TermProc]
[Suspicious.Path] Service.exe -- C:\Users\Jeleni\AppData\Local\Temp\AppLaunch\Service.exe[7] -> SMAZÁNO [TermProc]
¤¤¤ ¤¤¤ Záznamy Registrů: : 11 ¤¤¤
[Suspicious.Path] HKEY_USERS\S-1-5-21-345309842-932224804-3406310373-1000\Software\Microsoft\Windows\CurrentVersion\Run | WinDLL : C:\Users\Jeleni\AppData\Roaming\WinDLL.exe -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B97F51A2-EF34-41E4-8792-D5AE08E8171C} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B97F51A2-EF34-41E4-8792-D5AE08E8171C} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{B97F51A2-EF34-41E4-8792-D5AE08E8171C} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.StartMenu] HKEY_USERS\S-1-5-21-345309842-932224804-3406310373-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.HomePage] HKEY_USERS\S-1-5-21-345309842-932224804-3406310373-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.default-search.net?sid=498&a ... 13&src=hmp -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 1 (Driver: NAHRÁNO) ¤¤¤
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\cdrom @ \Device\CdRom0 (\SystemRoot\system32\DRIVERS\dtsoftbus01.sys)
¤¤¤ Webové prohlížeče : 2 ¤¤¤
[PUM.HomePage][FIREFX:Config] uxiurs5l.default : user_pref("browser.startup.homepage", "www.centrum.cz"); -> NALEZENO
[PUP][CHROME:Addon] Default : SweetPacks Chrome Extension [ogccgbmabaphcakpiclgcnmcnimhokcj] -> NALEZENO
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD6401AALS-00L3B2 ATA Device +++++
--- User ---
[MBR] 77884624b8bbb1ebd15033beaf1fc346
[BSP] 75e3bf7c7abc4d6af3b519db4d3768c7 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 610469 MB
User = LL1 ... OK
User = LL2 ... OK
RogueKiller V9.2.10.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7600 ) 32 bits version
Spuštěno v : Normální režim
Uživatel : Jeleni [Práva správce]
Mód : Kontrola -- Datum : 09/12/2014 16:48:08
¤¤¤ Škodlivé procesy: : 2 ¤¤¤
[Suspicious.Path] WinDLL.exe -- C:\Users\Jeleni\AppData\Roaming\WinDLL.exe[-] -> SMAZÁNO [TermProc]
[Suspicious.Path] Service.exe -- C:\Users\Jeleni\AppData\Local\Temp\AppLaunch\Service.exe[7] -> SMAZÁNO [TermProc]
¤¤¤ ¤¤¤ Záznamy Registrů: : 11 ¤¤¤
[Suspicious.Path] HKEY_USERS\S-1-5-21-345309842-932224804-3406310373-1000\Software\Microsoft\Windows\CurrentVersion\Run | WinDLL : C:\Users\Jeleni\AppData\Roaming\WinDLL.exe -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B97F51A2-EF34-41E4-8792-D5AE08E8171C} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B97F51A2-EF34-41E4-8792-D5AE08E8171C} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{B97F51A2-EF34-41E4-8792-D5AE08E8171C} | DhcpNameServer : 213.46.172.37 213.46.172.36 -> NALEZENO
[PUM.StartMenu] HKEY_USERS\S-1-5-21-345309842-932224804-3406310373-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.HomePage] HKEY_USERS\S-1-5-21-345309842-932224804-3406310373-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.default-search.net?sid=498&a ... 13&src=hmp -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 1 (Driver: NAHRÁNO) ¤¤¤
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\cdrom @ \Device\CdRom0 (\SystemRoot\system32\DRIVERS\dtsoftbus01.sys)
¤¤¤ Webové prohlížeče : 2 ¤¤¤
[PUM.HomePage][FIREFX:Config] uxiurs5l.default : user_pref("browser.startup.homepage", "www.centrum.cz"); -> NALEZENO
[PUP][CHROME:Addon] Default : SweetPacks Chrome Extension [ogccgbmabaphcakpiclgcnmcnimhokcj] -> NALEZENO
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD6401AALS-00L3B2 ATA Device +++++
--- User ---
[MBR] 77884624b8bbb1ebd15033beaf1fc346
[BSP] 75e3bf7c7abc4d6af3b519db4d3768c7 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 610469 MB
User = LL1 ... OK
User = LL2 ... OK
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Klávesnice píše dva háčky za sebou
jelis : založ si vlastní téma!
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Klávesnice píše dva háčky za sebou
nastav si QWERTY SLOVENSKE a mate to.
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 109 hostů