ComboFix 16-11-13.01 - top 01.12.2016 7:46.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8192.5935 [GMT 1:00]
Spuštěný z: c:\users\top\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-11-01 do 2016-12-01 )))))))))))))))))))))))))))))))
.
.
2016-12-01 06:55 . 2016-12-01 06:55 -------- d-----w- c:\users\Public\AppData\Local\temp
2016-12-01 06:55 . 2016-12-01 06:55 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2016-12-01 06:55 . 2016-12-01 06:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-12-01 06:38 . 2016-12-01 06:38 -------- d-----w- c:\users\top\AppData\Roaming\ProductData
2016-12-01 06:35 . 2016-12-01 06:13 24064 ----a-w- c:\windows\zoek-delete.exe
2016-12-01 06:35 . 2016-12-01 06:58 -------- d-----w- c:\users\top\AppData\Local\Temp
2016-12-01 06:35 . 2016-12-01 06:35 -------- d-----w- c:\programdata\ProductData
2016-12-01 06:13 . 2016-12-01 06:30 -------- d-----w- C:\zoek_backup
2016-11-30 17:19 . 2016-11-30 17:19 -------- d-----w- c:\programdata\Sophos
2016-11-30 17:18 . 2016-11-30 17:18 -------- d-----w- c:\program files (x86)\Sophos
2016-11-30 16:54 . 2016-11-30 16:54 -------- d-----w- c:\users\Default\AppData\Local\Trusteer
2016-11-30 09:41 . 2016-11-30 16:04 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-11-30 09:40 . 2016-11-30 09:41 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2016-11-30 09:40 . 2016-03-10 13:09 64896 ----a-w- c:\windows\system32\drivers\mwac.sys
2016-11-30 09:40 . 2016-03-10 13:08 140672 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2016-11-30 09:40 . 2016-03-10 13:08 27008 ----a-w- c:\windows\system32\drivers\mbam.sys
2016-11-30 09:29 . 2016-11-30 16:50 -------- d-----w- C:\AdwCleaner
2016-11-29 06:56 . 2016-11-29 06:57 -------- d-----w- c:\users\top\AppData\Local\ashampoo
2016-11-29 06:54 . 2016-11-29 06:54 -------- d-----w- c:\program files (x86)\Ashampoo
2016-11-28 17:11 . 2016-11-28 17:11 -------- d-----w- c:\users\top\AppData\Local\Star Stable 2
2016-11-28 17:10 . 2016-11-28 17:10 -------- d-----w- c:\program files (x86)\Stabenfeldt
2016-11-28 07:18 . 2016-11-28 07:18 -------- d-----w- c:\users\top\AppData\Roaming\Mikrotik
2016-11-18 06:14 . 2016-11-18 06:14 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2016-11-15 06:51 . 2016-10-06 16:49 235184 ----a-w- c:\windows\system32\drivers\RapportHades64.sys
2016-11-15 06:51 . 2016-10-06 16:49 489712 ----a-w- c:\windows\system32\drivers\RapportKE64.sys
2016-11-15 06:49 . 2016-11-15 06:49 -------- d-----w- c:\users\top\AppData\Local\Trusteer
2016-11-15 06:48 . 2016-11-15 06:48 -------- d-----w- c:\program files (x86)\Trusteer
2016-11-15 06:44 . 2016-11-15 06:44 -------- d-----w- c:\programdata\Trusteer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-12-01 05:37 . 2016-01-03 09:28 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2016-11-18 06:15 . 2016-11-18 06:15 345600 ----a-w- c:\windows\system32\schannel.dll
2016-11-18 06:15 . 2016-11-18 06:15 190464 ----a-w- c:\windows\system32\rpchttp.dll
2016-11-18 06:14 . 2016-11-18 06:14 254464 ----a-w- c:\windows\SysWow64\schannel.dll
2016-11-18 06:14 . 2016-11-18 06:14 141312 ----a-w- c:\windows\SysWow64\rpchttp.dll
2016-11-18 06:14 . 2016-11-18 06:14 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-11-09 14:11 . 2015-12-31 17:36 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-11-09 14:11 . 2015-12-31 17:36 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-11-09 10:35 . 2015-09-10 18:56 141011376 -c--a-w- c:\windows\system32\MRT.exe
2016-10-31 15:46 . 2015-12-31 17:05 110144 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2016-10-22 07:51 . 2016-10-22 07:51 756736 ----a-w- c:\windows\system32\win32spl.dll
2016-10-22 07:51 . 2016-10-22 07:51 497152 ----a-w- c:\windows\SysWow64\win32spl.dll
2016-10-22 07:51 . 2016-10-22 07:51 41984 ----a-w- c:\windows\system32\UtcResources.dll
2016-10-22 07:51 . 2016-10-22 07:51 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2016-10-22 07:51 . 2016-10-22 07:51 2048 ----a-w- c:\windows\system32\tzres.dll
2016-10-22 07:51 . 2016-10-22 07:51 1386496 ----a-w- c:\windows\system32\diagtrack.dll
2016-09-25 14:02 . 2016-09-25 14:02 988160 ----a-w- c:\windows\SysWow64\drmv2clt.dll
2016-09-25 14:02 . 2016-09-25 14:02 9728 ----a-w- c:\windows\system32\spwmp.dll
2016-09-25 14:02 . 2016-09-25 14:02 842240 ----a-w- c:\windows\system32\blackbox.dll
2016-09-25 14:02 . 2016-09-25 14:02 8192 ----a-w- c:\windows\SysWow64\spwmp.dll
2016-09-25 14:02 . 2016-09-25 14:02 782848 ----a-w- c:\windows\system32\wmdrmsdk.dll
2016-09-25 14:02 . 2016-09-25 14:02 744960 ----a-w- c:\windows\SysWow64\blackbox.dll
2016-09-25 14:02 . 2016-09-25 14:02 641024 ----a-w- c:\windows\system32\msscp.dll
2016-09-25 14:02 . 2016-09-25 14:02 617984 ----a-w- c:\windows\SysWow64\wmdrmsdk.dll
2016-09-25 14:02 . 2016-09-25 14:02 5120 ----a-w- c:\windows\system32\msdxm.ocx
2016-09-25 14:02 . 2016-09-25 14:02 5120 ----a-w- c:\windows\system32\dxmasf.dll
2016-09-25 14:02 . 2016-09-25 14:02 497664 ----a-w- c:\windows\system32\drmmgrtn.dll
2016-09-25 14:02 . 2016-09-25 14:02 4096 ----a-w- c:\windows\SysWow64\msdxm.ocx
2016-09-25 14:02 . 2016-09-25 14:02 4096 ----a-w- c:\windows\SysWow64\dxmasf.dll
2016-09-25 14:02 . 2016-09-25 14:02 406016 ----a-w- c:\windows\SysWow64\drmmgrtn.dll
2016-09-25 14:02 . 2016-09-25 14:02 325632 ----a-w- c:\windows\system32\msnetobj.dll
2016-09-25 14:02 . 2016-09-25 14:02 14632960 ----a-w- c:\windows\system32\wmp.dll
2016-09-25 14:02 . 2016-09-25 14:02 12574720 ----a-w- c:\windows\system32\wmploc.DLL
2016-09-25 14:02 . 2016-09-25 14:02 12574208 ----a-w- c:\windows\SysWow64\wmploc.DLL
2016-09-25 14:02 . 2016-09-25 14:02 1202176 ----a-w- c:\windows\system32\drmv2clt.dll
2016-09-25 14:02 . 2016-09-25 14:02 94440 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2016-09-25 14:02 . 2016-09-25 14:02 81920 ----a-w- c:\windows\system32\cryptsp.dll
2016-09-25 14:02 . 2016-09-25 14:02 54272 ----a-w- c:\windows\SysWow64\WsmRes.dll
2016-09-25 14:02 . 2016-09-25 14:02 54272 ----a-w- c:\windows\system32\WsmRes.dll
2016-09-25 14:02 . 2016-09-25 14:02 504320 ----a-w- c:\windows\SysWow64\msscp.dll
2016-09-25 14:02 . 2016-09-25 14:02 461312 ----a-w- c:\windows\system32\scavengeui.dll
2016-09-25 14:02 . 2016-09-25 14:02 433152 ----a-w- c:\windows\system32\mfplat.dll
2016-09-25 14:02 . 2016-09-25 14:02 354816 ----a-w- c:\windows\SysWow64\mfplat.dll
2016-09-25 14:02 . 2016-09-25 14:02 347136 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2016-09-25 14:02 . 2016-09-25 14:02 310784 ----a-w- c:\windows\system32\WsmWmiPl.dll
2016-09-25 14:02 . 2016-09-25 14:02 266752 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2016-09-25 14:02 . 2016-09-25 14:02 265216 ----a-w- c:\windows\SysWow64\msnetobj.dll
2016-09-25 14:02 . 2016-09-25 14:02 249344 ----a-w- c:\windows\SysWow64\WSManMigrationPlugin.dll
2016-09-25 14:02 . 2016-09-25 14:02 214016 ----a-w- c:\windows\SysWow64\WsmWmiPl.dll
2016-09-25 14:02 . 2016-09-25 14:02 2023424 ----a-w- c:\windows\system32\WsmSvc.dll
2016-09-25 14:02 . 2016-09-25 14:02 199168 ----a-w- c:\windows\SysWow64\WSManHTTPConfig.exe
2016-09-25 14:02 . 2016-09-25 14:02 182272 ----a-w- c:\windows\system32\WsmAuto.dll
2016-09-25 14:02 . 2016-09-25 14:02 146944 ----a-w- c:\windows\SysWow64\WsmAuto.dll
2016-09-25 14:02 . 2016-09-25 14:02 13824 ----a-w- c:\windows\system32\wsmprovhost.exe
2016-09-25 14:02 . 2016-09-25 14:02 12800 ----a-w- c:\windows\system32\wsmplpxy.dll
2016-09-25 14:02 . 2016-09-25 14:02 12288 ----a-w- c:\windows\SysWow64\wsmprovhost.exe
2016-09-25 14:02 . 2016-09-25 14:02 1178112 ----a-w- c:\windows\SysWow64\WsmSvc.dll
2016-09-25 14:02 . 2016-09-25 14:02 11264 ----a-w- c:\windows\system32\msmmsp.dll
2016-09-25 14:02 . 2016-09-25 14:02 1068544 ----a-w- c:\windows\system32\cryptui.dll
2016-09-25 14:02 . 2016-09-25 14:02 10240 ----a-w- c:\windows\SysWow64\wsmplpxy.dll
2016-09-25 14:02 . 2016-09-25 14:02 680448 ----a-w- c:\windows\system32\audiosrv.dll
2016-09-25 14:02 . 2016-09-25 14:02 663552 ----a-w- c:\windows\system32\drivers\PEAuth.sys
2016-09-25 14:02 . 2016-09-25 14:02 499712 ----a-w- c:\windows\system32\AUDIOKSE.dll
2016-09-25 14:02 . 2016-09-25 14:02 442368 ----a-w- c:\windows\SysWow64\AUDIOKSE.dll
2016-09-25 14:02 . 2016-09-25 14:02 374784 ----a-w- c:\windows\SysWow64\AudioEng.dll
2016-09-25 14:02 . 2016-09-25 14:02 295936 ----a-w- c:\windows\system32\AudioSes.dll
2016-09-25 14:02 . 2016-09-25 14:02 284672 ----a-w- c:\windows\system32\EncDump.dll
2016-09-25 14:02 . 2016-09-25 14:02 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2016-09-25 14:02 . 2016-09-25 14:02 195072 ----a-w- c:\windows\SysWow64\AudioSes.dll
2016-09-25 14:02 . 2016-09-25 14:02 9728 ----a-w- c:\windows\system32\pcalua.exe
2016-09-25 14:02 . 2016-09-25 14:02 8704 ----a-w- c:\windows\system32\pcaevts.dll
2016-09-25 14:02 . 2016-09-25 14:02 80896 ----a-w- c:\windows\SysWow64\cryptsp.dll
2016-09-25 14:02 . 2016-09-25 14:02 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
2016-09-25 14:02 . 2016-09-25 14:02 440320 ----a-w- c:\windows\system32\AudioEng.dll
2016-09-25 14:02 . 2016-09-25 14:02 37376 ----a-w- c:\windows\system32\pcadm.dll
2016-09-25 14:02 . 2016-09-25 14:02 371712 ----a-w- c:\windows\system32\qdvd.dll
2016-09-25 14:02 . 2016-09-25 14:02 3209216 ----a-w- c:\windows\SysWow64\mf.dll
2016-09-25 14:02 . 2016-09-25 14:02 187904 ----a-w- c:\windows\system32\pcasvc.dll
2016-09-25 14:02 . 2016-09-25 14:02 1573888 ----a-w- c:\windows\system32\quartz.dll
2016-09-25 14:02 . 2016-09-25 14:02 1329664 ----a-w- c:\windows\SysWow64\quartz.dll
2016-09-25 14:02 . 2016-09-25 14:02 125952 ----a-w- c:\windows\system32\audiodg.exe
2016-09-25 14:02 . 2016-09-25 14:02 11264 ----a-w- c:\windows\system32\pcawrk.exe
2016-09-25 14:02 . 2016-09-25 14:02 1005056 ----a-w- c:\windows\SysWow64\cryptui.dll
2016-09-25 14:02 . 2016-09-25 14:02 632320 ----a-w- c:\windows\system32\evr.dll
2016-09-25 14:02 . 2016-09-25 14:02 55808 ----a-w- c:\windows\system32\rrinstaller.exe
2016-09-25 14:02 . 2016-09-25 14:02 50176 ----a-w- c:\windows\SysWow64\rrinstaller.exe
2016-09-25 14:02 . 2016-09-25 14:02 489984 ----a-w- c:\windows\SysWow64\evr.dll
2016-09-25 14:02 . 2016-09-25 14:02 4121600 ----a-w- c:\windows\system32\mf.dll
2016-09-25 14:02 . 2016-09-25 14:02 24576 ----a-w- c:\windows\system32\mfpmp.exe
2016-09-25 14:02 . 2016-09-25 14:02 23040 ----a-w- c:\windows\SysWow64\mfpmp.exe
2016-09-25 14:02 . 2016-09-25 14:02 206848 ----a-w- c:\windows\system32\mfps.dll
2016-09-25 14:02 . 2016-09-25 14:02 2048 ----a-w- c:\windows\SysWow64\mferror.dll
2016-09-25 14:02 . 2016-09-25 14:02 2048 ----a-w- c:\windows\system32\mferror.dll
2016-09-25 14:02 . 2016-09-25 14:02 103424 ----a-w- c:\windows\SysWow64\mfps.dll
2016-09-25 14:00 . 2016-09-25 14:00 3229696 ----a-w- c:\windows\explorer.exe
2016-09-25 14:00 . 2016-09-25 14:00 2972672 ----a-w- c:\windows\SysWow64\explorer.exe
2016-09-25 14:00 . 2016-09-25 14:00 1941504 ----a-w- c:\windows\system32\authui.dll
2016-09-25 14:00 . 2016-09-25 14:00 1867776 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-09-25 14:00 . 2016-09-25 14:00 1806848 ----a-w- c:\windows\SysWow64\authui.dll
2016-09-25 14:00 . 2016-09-25 14:00 1499648 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2016-07-27 2023712]
"DAEMON Tools Lite Automount"="c:\program files\DAEMON Tools Lite\DTAgent.exe" [2015-06-18 4468056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-09-22 587288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2016-02-10 50599552]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R3 7ByteIo;7ByteIo; [x]
R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
R3 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
R3 cpuz135;cpuz135; [x]
R3 cpuz137;cpuz137; [x]
R3 cpuz138;cpuz138;c:\users\top\AppData\Local\Temp\cpuz138\cpuz138_x64.sys;c:\users\top\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MEDCServerComponent-Apache;MEDC Server Component - Apache;c:\manageengine\DesktopCentral_Server\apache\bin\dcserverhttpd.exe;c:\manageengine\DesktopCentral_Server\apache\bin\dcserverhttpd.exe [x]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsucx64.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssinstall;SInstalátor;c:\windows\SysWOW64\ssins.exe;c:\windows\SysWOW64\ssins.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wdm_usb;wdm_usb;c:\windows\system32\DRIVERS\usb2ser.sys;c:\windows\SYSNATIVE\DRIVERS\usb2ser.sys [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S0 RapportHades64;RapportHades64;c:\windows\System32\Drivers\RapportHades64.sys;c:\windows\SYSNATIVE\Drivers\RapportHades64.sys [x]
S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys;c:\windows\SYSNATIVE\Drivers\RapportKE64.sys [x]
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys;c:\windows\SYSNATIVE\DRIVERS\tdrpm258.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S1 RapportCerberus_1609053;RapportCerberus_1609053;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1609053.sys;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1609053.sys [x]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [x]
S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [x]
S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [x]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe [x]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2016-11-26 c:\windows\Tasks\Adobe Flash Player PPAPI Notifier.job
- c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe [2016-11-09 14:11]
.
2016-12-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-31 14:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2015-11-12 08:39 2472224 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-10-24 13662936]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-08 4030008]
.
------- Doplňkový sken -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
uStart Page =
hxxp://www.seznam.cz/mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{056D528D-CE28-4194-9BA3-BA2E9197FF8C} - (no file)
ShellIconOverlayIdentifiers-{05B38830-F4E9-4329-978B-1DD28605D202} - (no file)
ShellIconOverlayIdentifiers-{0596C850-7BDD-4C9D-AFDF-873BE6890637} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_207_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_207_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_207_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_207_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.23"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Trusteer\Rapport\bin\RapportService.exe
c:\program files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
.
**************************************************************************
.
Celkový čas: 2016-12-01 08:10:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2016-12-01 07:10
.
Před spuštěním: Volných bajtů: 35 218 735 104
Po spuštění: Volných bajtů: 34 700 677 120
.
- - End Of File - - 981F84168A7A255F38BB8F265FF33FD5
413FC2A0C716421B3158746D63736515