ComboFix 11-10-18.04 - Spike 18.10.2011 23:12:30.2.8 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.6141.4482 [GMT 2:00]
Spuštěný z: c:\users\Spike\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Spike\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.2 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
.
FILE ::
"c:\windows\AutoKMS.exe"
"K:\autorun.exe"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Spybot - Search & Destroy
c:\program files (x86)\Spybot - Search & Destroy\advcheck.dll
c:\program files (x86)\Spybot - Search & Destroy\aports.dll
c:\program files (x86)\Spybot - Search & Destroy\blindman.exe
c:\program files (x86)\Spybot - Search & Destroy\Default configuration.ini
c:\program files (x86)\Spybot - Search & Destroy\DelZip179.dll
c:\program files (x86)\Spybot - Search & Destroy\Dummies\dummy.cd_clint.dll
c:\program files (x86)\Spybot - Search & Destroy\Dummies\dummy.dap.gif
c:\program files (x86)\Spybot - Search & Destroy\Dummies\dummy.data.xml
c:\program files (x86)\Spybot - Search & Destroy\Dummies\dummy.default.gif
c:\program files (x86)\Spybot - Search & Destroy\Dummies\dummy.related.htm
c:\program files (x86)\Spybot - Search & Destroy\FJPZVIKVH.scr
c:\program files (x86)\Spybot - Search & Destroy\Help\Brasil.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Cesky.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Deutsch.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\English.chm
c:\program files (x86)\Spybot - Search & Destroy\Help\English.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Espanol.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Francais.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Hellenic.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Italiano.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Japanese.license.ansi.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Japanese.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Korean.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Nederlands.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Polski.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Russkiy.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Slovensky.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Srpski.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Help\Suomi.license.txt
c:\program files (x86)\Spybot - Search & Destroy\Includes\Adware.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\AdwareC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Browserpages.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\CLSIDs.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\Cookies.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Cookies.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\Dialer.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Dialer.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\DialerC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Domains.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\HeavyDuty.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Hijackers.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\HijackersC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\iPhone.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Keyloggers.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\KeyloggersC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Logs.uts
c:\program files (x86)\Spybot - Search & Destroy\Includes\LSP.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\LSP.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\Malware.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\MalwareC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\OperaPlugins.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\ProcWatch.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\PUPS.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\PUPSC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\RegWatch.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\RegXLinks.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\Revision.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Revision.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\Searchpages.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\Security.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\SecurityC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Services.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\Spybots.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\SpybotsC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Spyware.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\SpywareC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\Startup.tnfo
c:\program files (x86)\Spybot - Search & Destroy\Includes\Targets.nfo
c:\program files (x86)\Spybot - Search & Destroy\Includes\Tracks.uti
c:\program files (x86)\Spybot - Search & Destroy\Includes\Trojans.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\TrojansC-02.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\TrojansC-03.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\TrojansC-04.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\TrojansC-05.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\TrojansC.sbi
c:\program files (x86)\Spybot - Search & Destroy\Includes\TTLASSH.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\URL-Blacklist.sbs
c:\program files (x86)\Spybot - Search & Destroy\Includes\X509White.sbs
c:\program files (x86)\Spybot - Search & Destroy\Languages\Afrikaans.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Arabic.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Azeri.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Bahasa Indonesia.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Belarusskiy.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Bosanski.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Brasil.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Bulgarski.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Catalan.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Cesky.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Dansk.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Deutsch.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Eesti.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\English.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Espanol.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Esperanto.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Euskera.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Farsi.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Francais.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Furlan.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Galego.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Hebrew.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Hellenic.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Hindi.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Hrvatski.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Chinese (simplified).sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Chinese (traditional).sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Islenska.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Italiano.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Japanese.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Korean.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Latvian.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Letzebuergesch.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Lietuviu.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Magyar.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Makedonski.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Melayu.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Nederlands.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Norsk.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Polski.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Portugues.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Romaneste.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Russkiy.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Shqip.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Slovenscina.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Slovensky.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Srpski.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Suomi.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Svenska.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Thai.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Turkce.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Ukrainian.sbl
c:\program files (x86)\Spybot - Search & Destroy\Languages\Uzbek.sbl
c:\program files (x86)\Spybot - Search & Destroy\messages.zres
c:\program files (x86)\Spybot - Search & Destroy\OptOut.ini
c:\program files (x86)\Spybot - Search & Destroy\PCZTYXKRNUBXNUF.scr
c:\program files (x86)\Spybot - Search & Destroy\Plugins\Fennel.dll
c:\program files (x86)\Spybot - Search & Destroy\Plugins\Chai.dll
c:\program files (x86)\Spybot - Search & Destroy\Plugins\Mate.dll
c:\program files (x86)\Spybot - Search & Destroy\Plugins\TCPIPAddress.dll
c:\program files (x86)\Spybot - Search & Destroy\SDFiles.exe
c:\program files (x86)\Spybot - Search & Destroy\SDHelper.dll
c:\program files (x86)\Spybot - Search & Destroy\SDMain.exe
c:\program files (x86)\Spybot - Search & Destroy\SDUpdate.exe
c:\program files (x86)\Spybot - Search & Destroy\SIFBNAEPULEYWMQI.scr
c:\program files (x86)\Spybot - Search & Destroy\Skins\Colorblind.ini
c:\program files (x86)\Spybot - Search & Destroy\SpybotSD.exe
c:\program files (x86)\Spybot - Search & Destroy\sqlite3.dll
c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe
c:\program files (x86)\Spybot - Search & Destroy\Tools.dll
c:\program files (x86)\Spybot - Search & Destroy\unins000.dat
c:\program files (x86)\Spybot - Search & Destroy\unins000.exe
c:\program files (x86)\Spybot - Search & Destroy\unins000.msg
c:\program files (x86)\Spybot - Search & Destroy\UninsSrv.dll
c:\program files (x86)\Spybot - Search & Destroy\Update.exe
c:\program files (x86)\Spybot - Search & Destroy\Updates\advcheck165.exe
c:\program files (x86)\Spybot - Search & Destroy\Updates\advcheck165.zip
c:\program files (x86)\Spybot - Search & Destroy\Updates\clsid.zip
c:\program files (x86)\Spybot - Search & Destroy\Updates\downloaded.ini
c:\program files (x86)\Spybot - Search & Destroy\Updates\online.ini
c:\program files (x86)\Spybot - Search & Destroy\Updates\online.ini.uiz
c:\program files (x86)\Spybot - Search & Destroy\Updates\teatimer166.exe
c:\program files (x86)\Spybot - Search & Destroy\Updates\teatimer166.zip
c:\program files (x86)\Spybot - Search & Destroy\ZITIXGTEDBW.scr
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Configuration.ini
c:\programdata\Spybot - Search & Destroy\Excludes\Bots.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Cookies.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\FileExt.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Links.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\Single.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\SystemInternals.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\UpdateDL.sbe
c:\programdata\Spybot - Search & Destroy\Excludes\WaitFor.sbe
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\Checks.111017-0023.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.111017-0035.txt
c:\programdata\Spybot - Search & Destroy\Logs\Update downloads.log
c:\programdata\Spybot - Search & Destroy\Statistics.ini
c:\windows\AutoKMS.exe
c:\windows\system32\amicon.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-18 do 2011-10-18 )))))))))))))))))))))))))))))))
.
.
2011-10-18 21:16 . 2011-10-18 21:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-18 13:26 . 2011-10-18 13:31 -------- d-----w- c:\program files (x86)\Ubisoft
2011-10-18 08:58 . 2011-09-21 07:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{640A8F7E-7F0A-4A88-9FEC-1077DFA072AE}\mpengine.dll
2011-10-17 15:50 . 2011-10-17 15:50 -------- d-----w- c:\program files (x86)\HD Tune
2011-10-17 14:27 . 2011-10-17 14:27 -------- d-----w- c:\program files (x86)\Codec Pack - All In 1
2011-10-17 14:07 . 2011-10-17 14:07 -------- d-----w- c:\program files (x86)\MP3Gain
2011-10-17 13:50 . 2011-10-17 13:50 25640 ----a-w- c:\windows\etdrv.sys
2011-10-17 13:50 . 2011-10-17 13:50 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-10-17 13:46 . 2011-10-17 13:46 -------- d-----w- c:\programdata\InstallShield
2011-10-17 13:46 . 2005-02-17 05:15 73728 ----a-w- c:\windows\SysWow64\ISUSPM.cpl
2011-10-17 13:44 . 2010-04-06 14:30 31272 ----a-w- c:\windows\system32\AppleChargerSrv.exe
2011-10-17 13:44 . 2011-10-17 13:44 -------- d-----w- c:\program files\GIGABYTE
2011-10-17 13:44 . 2011-01-10 16:16 21104 ----a-w- c:\windows\system32\drivers\AppleCharger.sys
2011-10-17 12:58 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2011-10-17 12:58 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2011-10-17 12:47 . 2011-10-17 13:13 -------- d-----w- c:\program files (x86)\CrystalDiskInfo
2011-10-17 09:14 . 2011-10-17 09:14 -------- d-----w- c:\windows\SysWow64\Wat
2011-10-17 09:14 . 2011-10-17 09:14 -------- d-----w- c:\windows\system32\Wat
2011-10-16 22:32 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2011-10-16 22:32 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2011-10-16 22:26 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-10-16 22:26 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-10-16 22:26 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-10-16 22:26 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-10-16 22:26 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-10-16 22:26 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-10-16 22:26 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-10-16 22:26 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-10-16 22:26 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-10-16 22:26 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-10-16 22:26 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-10-16 22:20 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2011-10-16 22:20 . 2011-02-18 06:33 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-10-16 22:20 . 2011-02-18 05:33 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
2011-10-16 22:17 . 2010-11-02 05:17 473600 ----a-w- c:\windows\system32\taskcomp.dll
2011-10-16 22:16 . 2010-11-02 05:12 1837568 ----a-w- c:\windows\system32\d3d10warp.dll
2011-10-16 22:15 . 2011-05-03 05:21 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-16 22:14 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
2011-10-16 22:14 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
2011-10-16 22:14 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-10-16 22:14 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-10-16 22:14 . 2010-10-16 05:16 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-10-16 22:14 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-10-16 22:14 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2011-10-16 22:14 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2011-10-16 22:14 . 2010-10-16 04:33 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2011-10-16 22:14 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2011-10-16 22:13 . 2011-08-27 05:40 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-16 22:13 . 2011-08-27 05:40 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-10-16 22:13 . 2011-08-27 04:43 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-16 22:13 . 2011-08-27 04:43 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2011-10-16 22:12 . 2010-08-27 06:14 236032 ----a-w- c:\windows\system32\srvsvc.dll
2011-10-16 22:12 . 2010-08-27 05:46 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2011-10-16 22:12 . 2011-06-23 05:29 5507968 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-16 22:12 . 2011-06-23 04:38 3957120 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-10-16 22:12 . 2011-06-23 04:38 3902336 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-10-16 11:56 . 2011-10-16 11:56 -------- d-----w- c:\program files (x86)\FreeTime
2011-10-16 10:04 . 2011-10-16 10:04 -------- d-----w- c:\windows\system32\oodag
2011-10-15 22:33 . 2011-10-15 22:33 -------- d-----w- c:\program files (x86)\Mumble
2011-10-15 14:19 . 2011-10-15 14:19 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2011-10-15 14:05 . 2011-10-15 14:05 -------- d-----w- c:\programdata\Xfire
2011-10-15 14:05 . 2011-10-15 14:05 -------- d-----w- c:\program files (x86)\Xfire
2011-10-15 14:02 . 2011-10-17 21:16 -------- d-----w- C:\HRY
2011-10-15 14:00 . 2011-10-15 14:00 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-10-15 14:00 . 2011-10-15 14:00 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-10-15 13:47 . 2011-10-18 20:34 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-10-15 13:38 . 2011-10-15 13:38 -------- d-----w- c:\program files\OO Software
2011-10-15 13:06 . 2011-10-15 13:06 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-10-15 13:06 . 2011-10-15 13:06 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-10-15 13:06 . 2011-10-15 13:06 -------- d-----w- c:\program files (x86)\Java
2011-10-15 12:56 . 2011-10-15 12:56 -------- d-----w- c:\programdata\ROCCAT
2011-10-15 12:50 . 2011-10-15 12:50 -------- d-----w- c:\program files (x86)\ROCCAT
2011-10-15 12:32 . 2011-10-15 12:32 -------- d-----r- C:\MSOCache
2011-10-15 12:32 . 2011-10-15 11:40 -------- d-----w- c:\windows\Panther
2011-10-15 12:32 . 2011-10-15 12:32 -------- d-----w- C:\Boot
2011-10-15 12:31 . 2011-10-15 12:31 -------- d-----w- c:\program files (x86)\The KMPlayer
2011-10-15 12:25 . 2011-10-16 11:49 -------- d-----w- c:\program files (x86)\Internet Download Manager
2011-10-15 12:20 . 2011-10-15 12:57 -------- d-----w- c:\program files (x86)\ICQ7.6
2011-10-15 12:19 . 2011-10-15 12:19 -------- d-----w- c:\program files (x86)\VideoLAN
2011-10-15 12:19 . 2011-10-15 14:34 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-10-15 12:19 . 2011-10-18 21:17 -------- d-----w- c:\program files (x86)\Steam
2011-10-15 12:19 . 2011-10-15 12:19 -------- d-----w- c:\program files\CCleaner
2011-10-15 12:16 . 2011-10-15 12:16 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-15 12:16 . 2011-10-15 12:16 -------- d-----w- c:\windows\SysWow64\Macromed
2011-10-15 12:16 . 2011-10-15 12:16 -------- d-----w- c:\windows\system32\Macromed
2011-10-15 12:14 . 2011-05-24 17:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-10-15 12:12 . 2011-10-15 12:12 -------- d-----w- c:\users\UpdatusUser
2011-10-15 12:11 . 2011-10-15 12:12 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2011-10-15 12:04 . 2011-10-15 12:04 -------- d-----w- c:\program files\ESET
2011-10-15 12:03 . 2011-10-15 12:11 -------- d-----w- c:\program files\NVIDIA Corporation
2011-10-15 12:03 . 2011-10-15 12:03 -------- d-----w- C:\NVIDIA
2011-10-15 12:00 . 2011-10-15 12:00 -------- d-----w- C:\totalcmd
2011-10-15 12:00 . 2010-12-17 05:56 545 ----a-w- c:\windows\UC.PIF
2011-10-15 12:00 . 2010-12-17 05:56 545 ----a-w- c:\windows\RAR.PIF
2011-10-15 12:00 . 2010-12-17 05:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-10-15 12:00 . 2010-12-17 05:56 545 ----a-w- c:\windows\LHA.PIF
2011-10-15 12:00 . 2010-12-17 05:56 545 ----a-w- c:\windows\ARJ.PIF
2011-10-15 11:59 . 2011-10-15 11:59 -------- d-----w- c:\program files (x86)\Multimedia Card Reader
2011-10-15 11:59 . 2011-10-15 11:59 -------- d-----w- c:\windows\Downloaded Installations
2011-10-15 11:58 . 2011-10-18 13:32 -------- d-sh--w- c:\windows\Installer
2011-10-15 11:54 . 2011-10-15 11:54 -------- d-----w- C:\RaidTool
2011-10-15 11:54 . 2008-11-04 02:21 98144 ----a-w- c:\windows\system32\drivers\jraid.sys
2011-10-15 11:53 . 2011-10-15 11:54 -------- d-----w- c:\windows\RaidTool
2011-10-15 11:49 . 2011-10-15 11:49 -------- d-----w- c:\program files (x86)\Intel
2011-10-15 11:49 . 2010-03-02 08:04 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2011-10-15 11:49 . 2011-10-15 11:49 -------- d-----w- C:\Intel
2011-10-15 11:49 . 2011-10-15 11:49 -------- d-----w- c:\program files (x86)\Browser Configuration Utility
2011-10-15 11:49 . 2008-05-02 13:08 146528 ----a-w- c:\windows\SysWow64\dvmurl.dll
2011-10-15 11:48 . 2011-10-18 13:31 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2011-10-15 11:48 . 2011-10-17 13:47 -------- d-----w- c:\program files (x86)\GIGABYTE
2011-10-15 11:48 . 2011-10-17 13:46 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2011-10-15 11:47 . 2011-10-18 21:17 24072 ----a-w- c:\windows\gdrv.sys
2011-10-15 11:41 . 2011-10-15 13:56 -------- d-----w- c:\users\Spike
2011-10-13 20:30 . 2011-10-13 20:30 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2011-10-13 20:30 . 2011-10-13 20:30 28056 ----a-w- c:\windows\system32\xfcodec64.dll
2011-10-01 14:11 . 2011-07-06 15:14 145008 ----a-w- c:\windows\system32\drivers\idmwfp.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-18 17:19 . 2011-09-18 17:19 2249032 ----a-w- c:\windows\system32\ooscrsav.scr
2011-09-18 17:18 . 2011-09-18 17:18 350024 ----a-w- c:\windows\system32\oodbs.exe
2011-09-18 17:17 . 2011-09-18 17:17 535880 ----a-w- c:\windows\system32\oodssrs.dll
2011-09-18 17:16 . 2011-09-18 17:16 9544 ----a-w- c:\windows\system32\oodbsrs.dll
2011-08-03 11:50 . 2009-07-13 21:59 8355944 ----a-w- c:\windows\system32\nvwgf2umx.dll
2011-08-03 01:31 . 2011-08-03 01:31 311912 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-18_20.34.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-15 11:48 . 2011-10-18 20:35 24476 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-10-18 20:35 29064 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:46 . 2011-10-18 20:41 71944 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2011-10-15 11:43 . 2011-10-18 20:34 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-10-15 11:43 . 2011-10-18 21:05 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-10-15 11:43 . 2011-10-18 20:34 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-10-15 11:43 . 2011-10-18 21:05 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-10-18 20:33 . 2011-10-18 20:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-10-18 21:17 . 2011-10-18 21:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2011-10-18 20:40 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-10-18 13:03 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2011-10-18 20:40 631054 c:\windows\system32\perfh005.dat
- 2009-07-14 15:18 . 2011-10-18 13:03 631054 c:\windows\system32\perfh005.dat
- 2009-07-14 02:36 . 2011-10-18 13:03 106190 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-10-18 20:40 106190 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2011-10-18 20:40 121708 c:\windows\system32\perfc005.dat
- 2009-07-14 15:18 . 2011-10-18 13:03 121708 c:\windows\system32\perfc005.dat
- 2009-07-14 05:01 . 2011-10-18 20:32 385508 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-10-18 21:16 385508 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:34 . 2011-10-18 09:08 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-10-18 20:47 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2011-10-15 12:54 . 2011-10-18 21:16 10036237 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1708949124-2915336650-3997203911-1001-8192.dat
- 2011-10-15 12:54 . 2011-10-18 20:32 10036237 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1708949124-2915336650-3997203911-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-10-15 1242448]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2011-10-01 3425688]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 GEST Service;GEST Service for program management.;c:\program files (x86)\GIGABYTE\EnergySaver\GSvr.exe [2008-12-08 68136]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2011-10-17 25640]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-10-17 30528]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2011-08-22 57344]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2010-04-07 810120]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [x]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-09-18 3271496]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-05-30 16:50 22408 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RAVCpl64.exe" [2008-07-24 6452256]
"Skytel"="Skytel.exe" [2008-07-24 1833504]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2839840]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2011-09-18 3993416]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Stáhnout s IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Spike\AppData\Roaming\Mozilla\Firefox\Profiles\mdwk24tp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/FF - prefs.js: keyword.URL -
hxxp://www.google.com/search?ie=UTF-8&o ... &gfns=1&q=.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files (x86)\Spybot - Search & Destroy\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG15.00.00.01PROFESSIONAL"="48974BB290AD9FE873FE7261DDD1A4A5ED4FEA4B8134455F9091DE988F701FEC4D8F0D3FFC9152A6E1446E21566AF2A614A062ED86497A598023FA5F2AEDD7E1F73A44C3FA590A426FF8AECE42E84767001B7FCAE045BAED6F59D00C669A4C4B5610A8BA35287DB8CAB3956CBC1E53F79D0FE8893E45CE612CE271881F80FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6A0AC4980AC7933A9C6AECB7A5D14075D575E7D6A3B9808B9D60493627F50CE7C55D4DA9B8497BD253E291CDCDBBFC6526F289B4665DC2CCF5A9ABCE2D8B9120C09BC9DE489357FA98B9CF4F863A0A3139C084FAACABCFB27290B095642BB37F7A27EAD2BE5DC778F17A5903C2E0CDDCB2A5ECDA58F1FE5C9CE5E043E5A991363DE8371D7FD80EAB1F4AED2180746453021B597D07FBBE66266606B7C931B6D100FF886B9099B8D0D4A64D3E289989B971B5CE2ACBFCBEDC01F2032DAB30B8568984C3B8191A80AC3D03961D7A75219FCC9639A9DC28D6059BEEE7D86583A8AF874B41444F929FE1CD6607A9525C4677E6E2159E8544694C49CE4A90E6DFB2374AFA7477BF4A1FC7F40D4D41D9A4426DE6131F2BB1239D6BC26DDC4E73628E52D6C63C005899B8BFC81D1D75676ABE9868D70ECA36D34E7A2DAF8106A4B9AE19DDF679FA1142224C4255A228B77D7B60072817E162B047BFACD1804D396B197E25377B8F644C6B5AD4A33026933AB0AF7224A18E9E5FAB96B2AE34AC355D17CBBA29B928F9E1F9F32A3E47D83120BD2C3467559D88DF03E41A94640BE1CE2788F402069D6F842BA6E76BBCB5052E0F1D91870988460C01AED9C6F7AAB51516966B2162B1F02CC50A69BCB5AAA031BC0D3676D5F6FF4C7500369513ED9AF0CA0EC10CFFC9E37E01D3E05E64ACF0A2A88F118E2EA813769D8B807248677450562F388E737ECECA1D4C1B1A86E639F048A17200C2D05620C21EB0163011AF4B6E7F0DCB862894B391C5D3AEB506AD024F7C90DE4C9A90B9A871CF84D123AF71BDDFBE06240D4CCD28EE2C6D4AD517E057735FB311D831483606DA2654EB2D53266D2FE4AC413C39F39499646F3E45C2B2528A0F5B30BB7B9F327467201C4ED8095D5B49715EFD1D49DA9FC694AD6749A9015437ECE988534FEB5BF002995758B758913B60F776F2B33425F2C08BFA35D3B133DD8636DDE6CB0A801DCF72DEFE101193ED7C09B685DE17437C03B981A019CDC80D59BADF7622EB30C9CD5F63B10AB4E71EE6FB0DCAE89C6931AA240DC1821528E8C555E5B970D2F7A175C44832CD91B783411713FE17C6217F233F8C33726F4FE5821ED67935C177865594A4D4D6216B425D07A58400016774715697C787F6DFC5445294EDF990B45E7D0206D8D95F59C7F0F4DC4974D547E"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.exe
.
**************************************************************************
.
Celkový čas: 2011-10-18 23:19:40 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-18 21:19
ComboFix2.txt 2011-10-18 20:37
.
Před spuštěním: Volných bajtů: 891 677 429 760
Po spuštění: Volných bajtů: 891 580 313 600
.
- - End Of File - - B781A65AAC963A815440657516652179
Nahr nˇ probŘhlo ŁspŘçnŘ
Intel Core i5 2550K 3,40GHz|GIGABYTE GA-Z77X-UD4H|ASUS nVidia GTX660 TI-DC2-2GD5|Kingston HyperX Beast 16GB| GELID Solutions Tranquillo Rev. 2|ASUS BW-12B1ST|Corsair ATX 650W TX650 V2|Kingston SSDNow V300 120GB|WD Black 1TB | Nanoxia Deep Silence 1|Logitech G110|Razer Charcharias|Roccat Kone [+]|Roccat Apuri