ComboFix 15-11-30.01 - Acer . 12. 2015 15:24:22.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1029.18.2937.2201 [GMT 1:00]
Running from: c:\users\Acer\Desktop\ComboFix.exe
Command switches used :: c:\users\Acer\Desktop\CFScript.txt
AV: ESET Smart Security 8.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personálny Firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 8.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\Adobe Flash Player Updater.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0423244b249d4.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore1d090ca926a368f.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0e1897051fc9d.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA1d04232455688c7.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA1d0e18970e591ee.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.28.15\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.28.15\GoogleUpdate.exe
c:\program files\Google\Update\1.3.28.15\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.28.15\GoogleUpdateComRegisterShell64.exe
c:\program files\Google\Update\1.3.28.15\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.28.15\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.28.15\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.28.15\GoogleUpdateWebPlugin.exe
c:\program files\Google\Update\1.3.28.15\goopdate.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_am.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ar.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_bg.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_bn.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ca.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_cs.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_da.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_de.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_el.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_en.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_es.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_et.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_fa.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_fi.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_fil.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_fr.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_gu.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_hi.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_hr.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_hu.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_id.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_is.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_it.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_iw.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ja.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_kn.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ko.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_lt.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_lv.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ml.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_mr.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ms.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_nl.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_no.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_pl.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ro.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ru.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_sk.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_sl.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_sr.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_sv.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_sw.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ta.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_te.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_th.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_tr.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_uk.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_ur.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_vi.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.28.15\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.28.15\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.28.15\psmachine.dll
c:\program files\Google\Update\1.3.28.15\psmachine_64.dll
c:\program files\Google\Update\1.3.28.15\psuser.dll
c:\program files\Google\Update\1.3.28.15\psuser_64.dll
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.28.15\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\46.0.2490.86\46.0.2490.86_46.0.2490.80_chrome_updater.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Google\Update\Install\{04493FCD-0F53-4122-BE06-B6BAD7637CE4}\46.0.2490.86_46.0.2490.80_chrome_updater.exe
c:\program files\Google\Update\Install\{1F42704C-D9F7-4A33-A933-B11AA0C38A9D}\44.0.2403.107_43.0.2357.134_chrome_updater.exe
c:\program files\Google\Update\Install\{21A66057-B97D-4D70-87DF-68A9B9FD06DC}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{2ECCE782-0018-4D2B-BCC5-01FEC8B5447A}\42.0.2311.135_42.0.2311.90_chrome_updater.exe
c:\program files\Google\Update\Install\{4332D1CA-E443-4F9F-94E8-9E6A50B805CB}\43.0.2357.134_43.0.2357.132_chrome_updater.exe
c:\program files\Google\Update\Install\{4B8D232C-2BA7-43BE-821A-97BF2DEC7113}\42.0.2311.90_41.0.2272.118_chrome_updater.exe
c:\program files\Google\Update\Install\{5BE64F71-B6D0-4FB2-A098-E84587A35316}\41.0.2272.101_41.0.2272.89_chrome_updater.exe
c:\program files\Google\Update\Install\{61AF2B3A-34AF-401B-86C5-A7545E0D01AB}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{66482936-3317-4435-B57D-F1A4D6E21F0D}\41.0.2272.118_41.0.2272.101_chrome_updater.exe
c:\program files\Google\Update\Install\{6EED86C7-E9FA-4646-BA6A-580D2C9A759A}\43.0.2357.130_43.0.2357.124_chrome_updater.exe
c:\program files\Google\Update\Install\{6FD856ED-5D73-4315-A157-9D912CB28F56}\44.0.2403.130_44.0.2403.125_chrome_updater.exe
c:\program files\Google\Update\Install\{74A74055-1DD4-4213-8F01-656C00D0389F}\43.0.2357.124_43.0.2357.81_chrome_updater.exe
c:\program files\Google\Update\Install\{89CCFB3F-55D2-48AF-ACD0-14EAF5DA5FD7}\43.0.2357.81_43.0.2357.65_chrome_updater.exe
c:\program files\Google\Update\Install\{8A8F2471-AF30-43B3-B2D2-1BF7234339EF}\45.0.2454.93_45.0.2454.85_chrome_updater.exe
c:\program files\Google\Update\Install\{8C174BE3-1CA5-43F6-A0A9-9B253540B570}\43.0.2357.65_42.0.2311.152_chrome_updater.exe
c:\program files\Google\Update\Install\{965942AF-4C18-4D5E-8304-785B249E89F1}\46.0.2490.80_46.0.2490.71_chrome_updater.exe
c:\program files\Google\Update\Install\{9D6C3565-26F2-4DD1-ABF8-2DB11C3C65EE}\44.0.2403.125_44.0.2403.107_chrome_updater.exe
c:\program files\Google\Update\Install\{9D9228E9-08D3-4038-9032-512A42EF0809}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{9DBD9886-86D9-4ED8-8C19-17C7704CEC56}\46.0.2490.71_45.0.2454.101_chrome_updater.exe
c:\program files\Google\Update\Install\{A2D758EB-3137-4CED-AF87-93262CB22757}\45.0.2454.85_44.0.2403.157_chrome_updater.exe
c:\program files\Google\Update\Install\{B2AD3219-84E9-47E0-9CF1-8668C0DE6914}\44.0.2403.157_44.0.2403.155_chrome_updater.exe
c:\program files\Google\Update\Install\{BA66BD7D-DC71-4824-B0FB-3011A9A7F898}\45.0.2454.99_45.0.2454.93_chrome_updater.exe
c:\program files\Google\Update\Install\{C3F0DA6A-0F37-4672-9EF1-0C9EBC6FB935}\40.0.2214.115_40.0.2214.111_chrome_updater.exe
c:\program files\Google\Update\Install\{C45E7063-3488-4857-8B9A-8EC82F0B1D9B}\43.0.2357.132_43.0.2357.130_chrome_updater.exe
c:\program files\Google\Update\Install\{C576FCFE-076F-45E3-851C-25650C3EF5B8}\45.0.2454.101_45.0.2454.99_chrome_updater.exe
c:\program files\Google\Update\Install\{D83E4014-2B0A-43CA-B619-F03E478B765F}\41.0.2272.89_40.0.2214.115_chrome_updater.exe
c:\program files\Google\Update\Install\{DAE8E7DA-60D3-4BBB-A90B-E176390B3794}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{E8115EFD-60DA-44E3-91AC-AAEAB1A3E0AF}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{F29EE8CC-A68B-4154-8D97-0CBAEC899B20}\42.0.2311.152_42.0.2311.135_chrome_updater.exe
c:\program files\Google\Update\Install\{F2F8971B-EF42-4350-B813-7AF73A65DEF7}\44.0.2403.155_44.0.2403.130_chrome_updater.exe
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Files Created from 2015-11-02 to 2015-12-02 )))))))))))))))))))))))))))))))
.
.
2015-12-02 14:34 . 2015-12-02 14:37 -------- d-----w- c:\users\Acer\AppData\Local\temp
2015-12-01 16:07 . 2015-12-01 15:47 24064 ----a-w- c:\windows\zoek-delete.exe
2015-12-01 15:47 . 2015-12-01 16:10 -------- d-----w- C:\zoek_backup
2015-11-30 19:04 . 2015-12-01 15:24 30848 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-11-30 19:04 . 2015-11-30 21:14 -------- d-----w- c:\programdata\RogueKiller
2015-11-30 16:31 . 2015-12-01 16:15 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-11-30 16:31 . 2015-11-30 16:31 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-11-30 16:31 . 2015-11-30 16:31 -------- d-----w- c:\programdata\Malwarebytes
2015-11-30 16:31 . 2015-10-05 08:50 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-11-30 16:31 . 2015-10-05 08:50 94936 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-11-30 16:31 . 2015-10-05 08:50 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-11-30 16:23 . 2015-11-30 18:35 -------- d-----w- C:\AdwCleaner
2015-11-29 17:24 . 2015-11-29 17:24 -------- d-----w- c:\users\Acer\AppData\Roaming\CAD-KAS
2015-11-29 17:24 . 2015-11-29 17:24 82064 ----a-w- c:\windows\cadkasdeinst01e.exe
2015-11-12 19:45 . 2015-11-03 17:46 2386944 ----a-w- c:\windows\system32\win32k.sys
2015-11-12 15:09 . 2015-11-12 15:09 -------- d-----w- c:\program files\Common Files\AV
2015-11-11 15:22 . 2015-10-13 16:31 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2015-11-11 15:22 . 2015-10-13 16:31 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
2015-11-11 15:20 . 2015-10-13 04:50 712640 ----a-w- c:\windows\system32\drivers\ndis.sys
2015-11-11 15:19 . 2015-10-20 17:46 2955776 ----a-w- c:\windows\system32\wucltux.dll
2015-11-11 15:19 . 2015-10-20 17:46 2061824 ----a-w- c:\windows\system32\wuaueng.dll
2015-11-07 00:00 . 2015-11-07 00:00 -------- d-----w- C:\$WINDOWS.~BT
2015-11-06 22:32 . 2015-11-06 22:32 -------- d-----w- C:\$Windows.~WS
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-10-20 00:45 . 2015-11-11 15:21 251392 ----a-w- c:\windows\system32\schannel.dll
2015-10-13 00:29 . 2015-10-13 00:29 875720 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-10-01 17:50 . 2015-10-14 12:54 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-10-01 17:50 . 2015-10-14 12:54 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-10-01 17:50 . 2015-10-14 12:54 28160 ----a-w- c:\windows\system32\appidsvc.dll
2015-10-01 17:50 . 2015-10-14 12:54 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-10-01 17:50 . 2015-10-14 12:54 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-10-01 16:53 . 2015-10-14 12:54 50176 ----a-w- c:\windows\system32\drivers\appid.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\steam.exe" [2015-11-10 3011152]
"TeamSpeak 3 Client"="c:\program files\TeamSpeak 3 Client\ts3client_win32.exe" [2015-10-26 9953256]
"cz.seznam.software.autoupdate"="c:\users\Acer\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\Acer\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2015-05-26 103080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2015-01-28 5088456]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-06-08 334896]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 167424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 144384]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2013-05-16 1062472]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2015-10-05 1135416]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-10-30 102912]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-10-05 51928]
R3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys [2012-11-08 16896]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2015-03-10 51824]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2015-03-10 193464]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2015-03-10 135808]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2015-03-10 37928]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-10-12 1433216]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-10-12 1773696]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2015-01-28 1349576]
S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2012-11-08 100232]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-13 50688]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-10-05 23256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
utcsvc REG_MULTI_SZ DiagTrack
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-11-11 19:14 997704 ----a-w- c:\program files\Google\Chrome\Application\46.0.2490.86\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-12-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-11 13:21]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1544396497-1932906371-3723611144-1000\Software\SecuROM\License information*]
"datasecu"=hex:f5,23,79,66,0b,e9,db,3b,56,7d,04,b6,5b,c6,ab,23,a1,18,f7,70,8e,
70,45,8e,9e,9a,36,c6,56,94,53,79,ba,e8,21,ed,15,24,4a,87,0a,d7,4a,dc,2b,4b,\
"rkeysecu"=hex:51,5f,05,99,76,7c,43,56,19,4c,f2,31,0d,1d,af,a5
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\conhost.exe
c:\windows\system32\igfxsrvc.exe
c:\users\Acer\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
c:\program files\Java\jre1.8.0_51\bin\jp2launcher.exe
.
**************************************************************************
.
Completion time: 2015-12-02 15:42:30 - machine was rebooted
ComboFix-quarantined-files.txt 2015-12-02 14:42
ComboFix2.txt 2015-12-01 16:31
.
Pre-Run: Volných bajtů: 73 866 276 864
Post-Run: Volných bajtů: 73 658 466 304
.
- - End Of File - - EA30BE96C5F2FE6526B31056E267DF06
A36C5E4F47E84449FF07ED3517B43A31
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:45:51, on 2. 12. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Users\Acer\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Windows\Explorer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Acer\Desktop\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [TeamSpeak 3 Client] "C:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Acer\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Acer\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
--
End of file - 4513 bytes
aswMBR version 1.0.1.2290 Copyright(c) 2014 AVAST Software
Run date: 2015-12-02 15:53:28
-----------------------------
15:53:28.419 OS Version: Windows 6.1.7601 Service Pack 1
15:53:28.419 Number of processors: 2 586 0x170A
15:53:28.434 ComputerName: ACER-PC UserName: Acer
15:53:29.682 Initialize success
15:53:29.682 VM: initialized successfully
15:53:29.682 VM: Intel CPU virtualization not supported
15:53:32.335 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
15:53:32.351 Disk 0 Vendor: WDC_WD3200BEVT-22ZCT0 11.01A11 Size: 305245MB BusType: 11
15:53:32.491 Disk 0 MBR read successfully
15:53:32.507 Disk 0 MBR scan
15:53:32.507 Disk 0 Windows 7 default MBR code
15:53:32.522 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
15:53:32.522 Disk 0 Boot: NTFS code=1
15:53:32.538 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 150144 MB offset 206848
15:53:32.569 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 154999 MB offset 307701760
15:53:32.569 Disk 0 scanning sectors +625139712
15:53:32.632 Disk 0 scanning C:\Windows\system32\drivers
15:53:39.340 Service scanning
15:53:43.115 Service ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys **LOCKED** 5
15:53:43.489 Service epfw C:\Windows\system32\DRIVERS\epfw.sys **LOCKED** 5
15:53:43.536 Service EpfwLWF C:\Windows\system32\DRIVERS\EpfwLWF.sys **LOCKED** 5
15:53:43.598 Service epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys **LOCKED** 5
15:53:53.192 Modules scanning
15:53:53.192 Disk 0 trace - called modules:
15:53:53.255 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys dxgkrnl.sys igdkmd32.sys dxgmms1.sys intelppm.sys
15:53:53.255 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x861029d0]
15:53:53.270 3 CLASSPNP.SYS[8afc259e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x86034908]
15:53:53.286 Disk 0 statistics 76748/0/0 @ 5,67 MB/s
15:53:53.286 Scan finished successfully
15:53:58.528 Disk 0 MBR has been saved successfully to "C:\Users\Acer\Desktop\MBR.dat"
15:53:58.528 The log file has been saved successfully to "C:\Users\Acer\Desktop\aswMBR.txt"