ComboFix 11-07-26.02 - Orc 26.07.2011 19:14:47.2.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4094.2783 [GMT 2:00]
Spuštěný z: c:\users\Orc\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Orc\Desktop\CFScript.txt.txt
AV: AVG Internet Security Business Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security Business Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\Dvbpws.dll
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-26 do 2011-07-26 )))))))))))))))))))))))))))))))
.
.
2011-07-26 17:21 . 2011-07-26 17:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-26 16:56 . 2011-07-26 16:56 -------- d-----w- c:\program files (x86)\FreeTime
2011-07-26 06:06 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\programdata\Malwarebytes
2011-07-26 06:06 . 2011-07-26 06:06 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-26 06:06 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-26 06:02 . 2011-07-26 06:02 -------- d-----w- c:\program files (x86)\Trend Micro
2011-07-26 05:41 . 2011-07-26 05:41 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\windows\PCHEALTH
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft Sync Framework
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-26 05:40 . 2011-07-26 05:40 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-07-26 05:39 . 2011-07-26 05:39 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-07-26 05:38 . 2011-07-26 05:38 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-07-26 05:37 . 2011-07-26 05:44 -------- d-----w- c:\programdata\Microsoft Help
2011-07-26 05:37 . 2011-07-26 05:37 -------- d-----r- C:\MSOCache
2011-07-25 14:04 . 2011-07-25 14:04 -------- d-----w- c:\program files (x86)\Webteh
2011-07-24 22:11 . 2011-03-30 11:05 35112 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2011-07-24 22:11 . 2011-01-12 09:42 16376 ----a-w- c:\windows\system32\drivers\TVMonitor.sys
2011-07-24 22:11 . 2011-07-24 22:11 -------- d-----w- c:\program files (x86)\TeamViewer
2011-07-24 20:43 . 2011-07-24 20:43 -------- d-----w- C:\$AVG
2011-07-24 20:27 . 2011-07-24 20:27 -------- d-----w- c:\program files (x86)\MozBackup
2011-07-24 11:23 . 2011-07-26 05:34 -------- d-----w- C:\Instalačky
2011-07-24 11:20 . 2011-07-24 11:22 -------- d-----w- c:\program files (x86)\coolpro2
2011-07-24 10:20 . 2011-07-24 10:20 -------- d-----w- C:\found.000
2011-07-23 22:33 . 2011-07-23 22:33 -------- d-----w- c:\program files (x86)\DNsoft.be
2011-07-23 22:09 . 2011-07-23 22:11 -------- d-----w- c:\program files (x86)\JDownloader
2011-07-23 21:38 . 2007-10-22 01:37 17928 ----a-w- c:\windows\SysWow64\X3DAudio1_2.dll
2011-07-23 21:28 . 2011-07-23 21:28 -------- d-----w- C:\Games
2011-07-23 20:50 . 2011-07-23 20:50 -------- d-----w- c:\program files (x86)\BitTorrent
2011-07-23 18:57 . 2011-04-28 03:58 552448 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-23 18:57 . 2011-04-28 03:58 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-23 10:42 . 2011-07-26 14:49 -------- d-----w- C:\WinFast WorkArea
2011-07-23 10:34 . 2011-07-23 10:35 -------- d-----w- c:\programdata\ArcSoft
2011-07-23 10:34 . 2005-07-16 00:35 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2011-07-23 10:34 . 2011-07-23 10:34 -------- d-----w- c:\program files (x86)\Common Files\Ulead Systems
2011-07-23 10:33 . 2008-08-13 07:35 20480 ----a-w- c:\program files\Windows Sidebar\Gadgets\PVR2Remote.Gadget\ClassLibrary1.dll
2011-07-23 10:33 . 2011-07-23 10:33 -------- d-----w- c:\program files\WinFast
2011-07-23 10:07 . 2007-07-13 10:28 116768 ----a-w- c:\windows\system32\NXPMV64.dll
2011-07-23 10:07 . 2011-07-23 10:07 -------- d-----w- c:\windows\SysWow64\WinFast
2011-07-23 10:07 . 2010-10-13 10:08 1345664 ----a-w- c:\windows\system32\drivers\3xHybr64.sys
2011-07-23 10:00 . 2011-07-23 10:00 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-23 09:59 . 2011-07-23 09:58 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-23 09:58 . 2011-07-23 09:58 -------- d-----w- c:\program files (x86)\Java
2011-07-23 09:46 . 2011-07-22 23:56 -------- d-----w- c:\windows\Panther
2011-07-23 09:46 . 2011-07-23 09:46 -------- d-----w- C:\Boot
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\SysWow64\Wat
2011-07-23 02:10 . 2011-07-23 02:10 -------- d-----w- c:\windows\system32\Wat
2011-07-23 01:50 . 2011-07-23 01:50 -------- d--h--w- c:\programdata\Common Files
2011-07-23 01:50 . 2011-07-23 01:51 -------- d-----w- c:\programdata\AVG Security Toolbar
2011-07-23 01:49 . 2011-07-23 01:49 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-07-23 01:48 . 2011-07-26 11:54 -------- d-----w- c:\windows\system32\drivers\AVG
2011-07-23 01:48 . 2011-07-23 01:50 -------- d-----w- c:\programdata\AVG10
2011-07-23 01:47 . 2011-07-23 01:47 -------- d-----w- c:\program files (x86)\AVG
2011-07-23 01:40 . 2011-07-23 01:51 -------- d-----w- c:\programdata\MFAData
2011-07-23 01:25 . 2011-07-23 01:25 -------- d-----w- c:\program files\Defraggler
2011-07-23 01:24 . 2011-07-23 01:24 -------- d-----w- c:\program files\CCleaner
2011-07-23 01:23 . 2011-07-23 01:24 -------- d-----w- c:\program files (x86)\Google
2011-07-23 01:22 . 2011-07-26 17:14 -------- d-sh--w- c:\windows\Installer
2011-07-23 01:20 . 2011-05-25 07:25 67176 ----a-w- c:\windows\system32\OpenCL.dll
2011-07-23 01:15 . 2011-06-01 03:16 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2011-07-23 01:15 . 2011-06-01 03:16 535656 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2011-07-23 01:15 . 2011-06-01 03:16 107624 ----a-w- c:\windows\system32\RTNUninst64.dll
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\windows\SysWow64\RTCOM
2011-07-23 01:14 . 2011-07-23 01:14 -------- d-----w- c:\program files\Realtek
2011-07-23 01:12 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-07-23 01:12 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-07-23 01:12 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-07-23 01:12 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-07-23 01:12 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-07-23 01:12 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-07-23 01:12 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-07-23 01:08 . 2011-07-23 02:16 -------- d-----w- C:\Cinema
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- c:\program files (x86)\Intel
2011-07-23 01:06 . 2010-03-02 08:04 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2011-07-23 01:06 . 2011-07-23 01:06 -------- d-----w- C:\Intel
2011-07-23 01:00 . 2011-07-23 01:00 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2011-07-23 00:52 . 2011-07-23 02:24 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-23 00:52 . 2011-07-23 00:52 -------- d-----w- c:\windows\SysWow64\Macromed
2011-07-23 00:21 . 2011-04-29 05:47 1110528 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-23 00:10 . 2009-12-29 08:03 220672 ----a-w- c:\windows\system32\wintrust.dll
2011-07-23 00:10 . 2009-12-29 06:55 172032 ----a-w- c:\windows\SysWow64\wintrust.dll
2011-07-23 00:09 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
2011-07-23 00:09 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
2011-07-23 00:06 . 2011-07-20 07:44 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E9B8650-EF5E-458F-BC37-C50C57A74E58}\mpengine.dll
2011-07-23 00:06 . 2011-05-24 17:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-07-22 23:56 . 2011-07-22 23:57 -------- d-----w- c:\users\Orc
2011-07-22 23:56 . 2011-07-22 23:56 -------- d-----w- C:\Recovery
2011-07-22 15:02 . 2011-07-23 02:17 -------- d-----w- C:\Moje
2011-07-22 14:40 . 2011-07-23 21:28 -------- d-----w- C:\Hry
2011-07-20 08:11 . 2011-07-23 00:39 -------- d-----w- C:\Music
2011-07-20 08:00 . 2011-07-23 02:17 -------- d-----w- C:\Fotky
2011-07-20 07:58 . 2011-07-25 17:52 -------- d-----w- C:\Bramboráček
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-14 06:34 . 2011-07-23 00:20 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-26_08.55.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-07-23 02:16 . 2011-07-26 17:26 20182 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-26 17:26 37362 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:46 . 2011-07-26 11:41 83552 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2011-07-23 00:00 . 2011-07-26 04:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-07-23 00:00 . 2011-07-26 17:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-07-23 00:00 . 2011-07-26 04:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-23 00:00 . 2011-07-26 17:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-26 08:56 . 2011-07-26 08:56 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\01558bff07cd0456e5e5c96baab32109\stdole.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\95c38e066702d70c07858acbde86c07f\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 44544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\90dfce85a149f16578cbf64ef25e008c\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\80ea3b62aab874d48f46b5c67899caf7\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 89088 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\752b4e9d81e92fdc388b3d2fcc5b92ae\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 71680 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\73ef8ad5107d6e7b220fdaa592d29c19\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 84480 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\4d70553d106d0d9ec17a93c03b04f7ef\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 93696 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\16f2dec6422f65763f083feab13c5cbf\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 87040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\137c8f2489e83eb92230890ddb95e97e\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 44032 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\07afe14f79b0a1ffe3bda329992eed8f\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2011-07-23 00:00 . 2011-07-26 17:26 5720 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3097329092-3601139478-389757476-1001_UserData.bin
+ 2011-07-26 17:23 . 2011-07-26 17:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-26 04:42 . 2011-07-26 04:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-26 17:23 . 2011-07-26 17:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-26 04:42 . 2011-07-26 04:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-26 16:57 . 2002-12-06 06:02 272896 c:\windows\SysWOW64\pncrt.dll
- 2009-07-14 02:36 . 2011-07-26 04:46 606992 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-07-26 11:42 606992 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-07-26 11:42 103370 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-07-26 04:46 103370 c:\windows\system32\perfc009.dat
+ 2009-07-14 04:45 . 2011-07-26 11:38 414888 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 05:01 . 2011-07-26 17:21 396648 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-07-26 08:57 . 2011-07-26 08:57 777728 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\fcb9f8ec37aa8a7b38c603e4c4726e33\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 226816 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\e6ac4afe01d7e6c7e7fbc5c7de6514c3\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 390656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\df600168d7df7fe49010548f88487bd7\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 494592 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d4ce81cec345d704c6a8dc52f9537f48\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 305664 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c27ffd40384598eb87d60592b3e55d13\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 225280 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9a46d28e25c8fe56d1e43996399b65d0\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 232448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\7de97db945198aba3ece2dad79f52d0b\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 499200 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\753870602b09c109590a760737dbf386\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 230400 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\62e1319ee8ff2a56825e1cae8cebf3ce\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 125440 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\5caa4e0b3376c601cb7cb7faf9cbee53\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 202240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\4e3265456dfbcc75df09155efba7c434\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 209920 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\4c4d35f877f44a06d354d7420f73d095\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\21627a41da150a7960abea518c5bbf88\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 277504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\11660caf1493cfc791dd08ee4946ab70\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 970240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\0db3936e114cc6eafb286257f8075912\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\0d67d47b364e629d0b701336442d6f38\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\d267bd30e38638b50aafd348b1510f9c\Microsoft.Office.Tools.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 244224 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\25ca1c0d1c95549315495dc4ffa22818\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\7776f0878fd11bf3d82ca292f7f3338f\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\5ec72efeb5de80ecfded0ef5244e008a\ehiActivScp.ni.dll
+ 2009-07-14 04:45 . 2011-07-26 11:41 3897560 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2011-07-24 10:25 3897560 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2011-07-23 05:25 . 2011-07-26 17:21 8075352 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3097329092-3601139478-389757476-1001-12288.dat
+ 2011-07-26 08:57 . 2011-07-26 08:57 1877504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\18ca39ae10109ad46c3082f82bd56812\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 1875456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\73814ed343bc11f729af4038ea213559\Microsoft.Office.Tools.Excel.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 1093632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\52b581df7c2dce7a5daa3a0dcc8edead\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2011-07-26 08:57 . 2011-07-26 08:57 1186304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\32fdaa05af81a7d1cd7fc199d7203579\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2011-07-26 08:56 . 2011-07-26 08:56 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\8a8c7d6eb6109efcdaf31427dba23cb8\ehiVidCtl.ni.dll
- 2009-07-14 02:34 . 2011-07-26 05:43 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-07-26 11:52 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll [BU]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-05-30 09:33 2495816 ----a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
"{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}"= "c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll" [BU]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CLASSES_ROOT\clsid\{db4e9724-f518-4dfd-9c7c-78b52103cab9}]
[HKEY_CLASSES_ROOT\facemoods.dskBnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
[HKEY_CLASSES_ROOT\facemoods.dskBnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Shutdown_Manager"="c:\program files (x86)\DNsoft.be\Shutdown Scheduler\PC Shutdown.exe" [2007-03-23 1081344]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart
.
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23 136176]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-05-30 1025352]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG10\avgfws.exe [2011-03-09 2708024]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-25 2214504]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S3 3xHybr64;WinFast DTV1000 S;c:\windows\system32\DRIVERS\3xHybr64.sys [x]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S3 MonitorFunction;Driver for Monitor;c:\windows\system32\DRIVERS\TVMonitor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
hxxp://eu.ask.com/?l=dis&o=14597mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 88.146.189.14 88.146.189.10
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Orc\AppData\Roaming\Mozilla\Firefox\Profiles\6u95ym7x.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage -
hxxp://eu.ask.com/?l=dis&o=14597.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe
c:\program files (x86)\AVG\AVG10\avgam.exe
c:\program files (x86)\TeamViewer\Version6\tv_w32.exe
c:\program files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
.
**************************************************************************
.
Celkový čas: 2011-07-26 19:29:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-26 17:29
ComboFix2.txt 2011-07-26 08:59
.
Před spuštěním: 568 171 933 696 bytes free
Po spuštění: 567 887 503 360 bytes free
.
- - End Of File - - 5C39DE20C0EF62DC803E01B9BE338203