Prosím o kontrolu logu Hijackthis. Děkuji.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:52:13, on 24.4.2012
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Users\Anett\Downloads\hijackthis(2).exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arccosine.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
O4 - HKLM\..\Run: [SetDefaultSCR] C:\Program Files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE3972] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O4 - HKLM\..\RunOnce: [SpybotDeletingE2146] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O4 - HKCU\..\Run: [EPSON SX218 Series] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIGDE.EXE /FU "C:\windows\TEMP\E_S7984.tmp" /EF "HKCU"
O4 - HKCU\..\RunOnce: [SpybotDeletingF1254] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O4 - HKCU\..\RunOnce: [SpybotDeletingF2132] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS2\Services\Tcpip\..\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\windows\SysWOW64\guard32.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVRedirector - AVSoftware, Ltd - C:\Program Files (x86)\Hide The IP\data\AVLib.EXE
O23 - Service: Roxio File Backup Service (CEEBC40A-FDED-4C59-B354-939132350B01) - Unknown owner - C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hide The IP Service (htisvcfwm) - AVSoftware - C:\Program Files (x86)\Hide The IP\data\htisvc.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: MWAgent - MicroWorld Technologies Inc. - C:\PROGRA~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9979 bytes
Prosím o kontrolu logu Vyřešeno
-
- nováček
- Příspěvky: 29
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Problémy? Nevidím tam antivir
Odinstaluj SUPERAntiSpyware
Fixni:
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
Odinstaluj SUPERAntiSpyware
Fixni:
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arccosine.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE3972] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O4 - HKLM\..\RunOnce: [SpybotDeletingE2146] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O4 - HKCU\..\RunOnce: [SpybotDeletingF1254] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O4 - HKCU\..\RunOnce: [SpybotDeletingF2132] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Windows\setupact.log"
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (file missing)
O13 - Gopher Prefix:
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
-
- nováček
- Příspěvky: 29
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Jak myslíš není antivir? Před měsícem jsem si koupila licenci na Eset NOD32 a mám ho nainstalovalý.
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Verze databáze: v2012.04.24.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Anett :: PC-LENOVO [administrátor]
24.4.2012 12:30:56
mbam-log-2012-04-24 (12-30-56).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 205055
Uplynulý čas: 10 minut, 43 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Verze databáze: v2012.04.24.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Anett :: PC-LENOVO [administrátor]
24.4.2012 12:30:56
mbam-log-2012-04-24 (12-30-56).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 205055
Uplynulý čas: 10 minut, 43 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
A jo, přehlídl jsem službu. Pořád jsi ale nenapsala, co máš za problém
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
-
- nováček
- Příspěvky: 29
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Když jsem na internetu, tak se mi v poslední době stává, že mi úplně zamrzne počítač na pár sekund a nejde nic dělat. A poté je celý počítač několik dalších minut zpomalený. Nevíš, kde by mohl být problém?
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
-
- nováček
- Příspěvky: 29
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
ComboFix 12-04-24.02 - Anett 24.04.2012 16:09:25.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2666 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: COMODO Firewall *Disabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
SP: COMODO Defense+ *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Anett\AppData\Local\Microsoft\Windows\Temporary Internet Files\{54CEDD02-39CC-4407-831D-FE5146D1081A}.xps
c:\users\Anett\AppData\Local\Microsoft\Windows\Temporary Internet Files\{A36AAF3B-7E7B-48B4-A1B1-23917D3DE80D}.xps
c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\weave\toFetch
G:\Autorun.inf
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-24 14:15 . 2012-04-24 14:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-24 10:16 . 2012-04-24 10:16 -------- d---a-w- c:\windows\rundll16.exe
2012-04-24 10:16 . 2012-04-24 10:16 -------- d---a-w- c:\windows\logo1_.exe
2012-04-24 10:08 . 2012-04-24 10:08 34048 ----a-w- c:\windows\SysWow64\eEmpty.exe
2012-04-22 15:33 . 2012-04-22 15:33 -------- d-----w- c:\programdata\XoftSpySE
2012-04-22 14:55 . 2012-04-23 19:43 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-04-22 14:55 . 2012-04-22 16:57 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 17:00 . 2012-04-09 17:00 -------- d-----w- c:\users\Anett\AppData\Roaming\No Company Name
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-27 15:16 . 2012-03-27 15:16 -------- d-----w- c:\program files (x86)\MD5 Password
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-03-11 21:13 . 2011-12-19 17:59 43248 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2012-03-11 21:13 . 2011-12-19 17:59 577824 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2012-03-11 21:13 . 2011-12-19 17:59 22696 ----a-w- c:\windows\system32\drivers\cmderd.sys
2012-03-11 21:13 . 2011-12-19 17:58 41200 ----a-w- c:\windows\system32\cmdcsr.dll
2012-03-11 21:13 . 2011-12-19 17:58 301224 ----a-w- c:\windows\SysWow64\guard32.dll
2012-03-11 21:13 . 2011-12-19 17:58 389840 ----a-w- c:\windows\system32\guard64.dll
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 136176]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 136176]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
Obsah adresáře 'Naplánované úlohy'
.
2012-04-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 20:08]
.
2012-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 06:44]
.
2012-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 06:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 9569096]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://ww.w.adriaticonline.com/apartmen ... px?id=3624
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
[HKEY_USERS\S-1-5-21-42510566-1014113567-1088135144-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{76574FE3-C073-29A1-AEB2-AD11B9E08853}*]
"oafdgmpldkbdghnkmmdjmdjcobcfio"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,62,
64,6c,67,62,6c,67,00,8a
"papcijeilihpkddpohcknblnpmmiopgn"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,
62,64,6c,67,62,6c,67,00,8a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
c:\progra~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWAgent.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 16:20:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 527 981 645 824
Po spuštění: Volných bajtů: 528 259 133 440
.
- - End Of File - - B990CBAAC2AD67381322AC7C6E95B2BA
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2666 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: COMODO Firewall *Disabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
SP: COMODO Defense+ *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Anett\AppData\Local\Microsoft\Windows\Temporary Internet Files\{54CEDD02-39CC-4407-831D-FE5146D1081A}.xps
c:\users\Anett\AppData\Local\Microsoft\Windows\Temporary Internet Files\{A36AAF3B-7E7B-48B4-A1B1-23917D3DE80D}.xps
c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\weave\toFetch
G:\Autorun.inf
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-24 14:15 . 2012-04-24 14:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-24 10:16 . 2012-04-24 10:16 -------- d---a-w- c:\windows\rundll16.exe
2012-04-24 10:16 . 2012-04-24 10:16 -------- d---a-w- c:\windows\logo1_.exe
2012-04-24 10:08 . 2012-04-24 10:08 34048 ----a-w- c:\windows\SysWow64\eEmpty.exe
2012-04-22 15:33 . 2012-04-22 15:33 -------- d-----w- c:\programdata\XoftSpySE
2012-04-22 14:55 . 2012-04-23 19:43 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-04-22 14:55 . 2012-04-22 16:57 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 17:00 . 2012-04-09 17:00 -------- d-----w- c:\users\Anett\AppData\Roaming\No Company Name
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-27 15:16 . 2012-03-27 15:16 -------- d-----w- c:\program files (x86)\MD5 Password
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-03-11 21:13 . 2011-12-19 17:59 43248 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2012-03-11 21:13 . 2011-12-19 17:59 577824 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2012-03-11 21:13 . 2011-12-19 17:59 22696 ----a-w- c:\windows\system32\drivers\cmderd.sys
2012-03-11 21:13 . 2011-12-19 17:58 41200 ----a-w- c:\windows\system32\cmdcsr.dll
2012-03-11 21:13 . 2011-12-19 17:58 301224 ----a-w- c:\windows\SysWow64\guard32.dll
2012-03-11 21:13 . 2011-12-19 17:58 389840 ----a-w- c:\windows\system32\guard64.dll
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 136176]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 136176]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
Obsah adresáře 'Naplánované úlohy'
.
2012-04-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 20:08]
.
2012-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 06:44]
.
2012-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-26 06:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 9569096]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://ww.w.adriaticonline.com/apartmen ... px?id=3624
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
[HKEY_USERS\S-1-5-21-42510566-1014113567-1088135144-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{76574FE3-C073-29A1-AEB2-AD11B9E08853}*]
"oafdgmpldkbdghnkmmdjmdjcobcfio"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,62,
64,6c,67,62,6c,67,00,8a
"papcijeilihpkddpohcknblnpmmiopgn"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,
62,64,6c,67,62,6c,67,00,8a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
c:\progra~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWAgent.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 16:20:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 527 981 645 824
Po spuštění: Volných bajtů: 528 259 133 440
.
- - End Of File - - B990CBAAC2AD67381322AC7C6E95B2BA
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
SP: COMODO Defense+ *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Nech zaplý jen jeden antispyware, ostatní natvrdo vypni nebo odinstaluj
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
Toto otestuj na Virustotal
c:\windows\winsbak.reg
c:\windows\winsbak2.reg
c:\windows\killproc.exe
c:\windows\inst_tspx.exe
c:\windows\inst_tsp.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Nech zaplý jen jeden antispyware, ostatní natvrdo vypni nebo odinstaluj
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
DirLook::
c:\users\Anett\AppData\Roaming\No Company Name
Folder::
c:\windows\rundll16.exe
c:\windows\logo1_.exe
c:\programdata\XoftSpySE
c:\programdata\Spybot - Search & Destroy
c:\program files (x86)\Spybot - Search & Destroy
c:\program files (x86)\Google\Update
File::
c:\windows\SysWow64\eEmpty.exe
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Driver::
gupdate
gupdatem
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=-
Firefox::
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://ww.w.adriaticonline.com/apartmen ... px?id=3624
RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
Toto otestuj na Virustotal
c:\windows\winsbak.reg
c:\windows\winsbak2.reg
c:\windows\killproc.exe
c:\windows\inst_tspx.exe
c:\windows\inst_tsp.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
-
- nováček
- Příspěvky: 29
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
ComboFix 12-04-24.02 - Anett 24.04.2012 17:27:57.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2860 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Anett\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\SysWow64\eEmpty.exe"
"c:\windows\Tasks\Adobe Flash Player Updater.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.111\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.21.111\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.111\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.111\psuser.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.111\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\18.0.1025.162\chrome_updater.exe
c:\program files (x86)\Google\Update\Download\{FDDB16D7-2E25-45C3-9933-518AEC31E55A}\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Spybot - Search & Destroy
c:\program files (x86)\Spybot - Search & Destroy\advcheck.dll
c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe
c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\120422-190211.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\120423-220402.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Fixes.120422-1735.txt
c:\programdata\Spybot - Search & Destroy\Logs\Fixes.120422-1832.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120223-2202.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1657.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1714.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1738.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1819.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1819.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1832.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.121923-2219.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.122022-1920.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\Resident.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
c:\programdata\Spybot - Search & Destroy\ProcCache.sbc
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar.zip
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar1.zip
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar2.zip
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar3.zip
c:\programdata\XoftSpySE
c:\programdata\XoftSpySE\6\8B13A86E.plf
c:\programdata\XoftSpySE\6\Ignore.db
c:\programdata\XoftSpySE\6\Quarantine.db
c:\programdata\XoftSpySE\6\Stats.db
c:\windows\logo1_.exe
c:\windows\rundll16.exe
c:\windows\SysWow64\eEmpty.exe
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 17:00 . 2012-04-09 17:00 -------- d-----w- c:\users\Anett\AppData\Roaming\No Company Name
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-27 15:16 . 2012-03-27 15:16 -------- d-----w- c:\program files (x86)\MD5 Password
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\users\Anett\AppData\Roaming\No Company Name ----
.
2012-04-09 17:00 . 2012-04-09 17:00 12 ----a-w- c:\users\Anett\AppData\Roaming\No Company Name\No Client Name\No Client Internal Version\Trace Database.txt
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-24_14.17.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-24 15:22 65784 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 15:22 45330 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-11-14 15:16 . 2012-04-24 15:22 15858 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-42510566-1014113567-1088135144-1001_UserData.bin
+ 2011-11-14 15:22 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-24 15:32 . 2012-04-24 15:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-24 15:32 . 2012-04-24 15:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-04-24 14:16 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-24 15:31 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-11-14 09:25 . 2012-04-24 14:16 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
+ 2011-11-14 09:25 . 2012-04-24 15:31 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
"combofix"="c:\combofix\CF28718.3XE" [2010-11-21 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
[HKEY_USERS\S-1-5-21-42510566-1014113567-1088135144-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{76574FE3-C073-29A1-AEB2-AD11B9E08853}*]
"oafdgmpldkbdghnkmmdjmdjcobcfio"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,62,
64,6c,67,62,6c,67,00,8a
"papcijeilihpkddpohcknblnpmmiopgn"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,
62,64,6c,67,62,6c,67,00,8a
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
c:\progra~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWAgent.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 17:35:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 15:35
ComboFix2.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 529 398 931 456
Po spuštění: Volných bajtů: 528 816 902 144
.
- - End Of File - - 4D8980E7A79EC9082593E1E975864028
Ten SP: Windows Defender jsem předtím odinstalovala, ale pořád se tam ukazuje.
Virustotal:
c:\windows\killproc.exe
https://www.virustotal.com/file/9f575ec ... 335283118/
c:\windows\inst_tsp.exe
https://www.virustotal.com/file/e929115 ... 335282505/
Ostatní tři soubory jsou ve Virustotal čisté.
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2860 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Anett\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\SysWow64\eEmpty.exe"
"c:\windows\Tasks\Adobe Flash Player Updater.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.111\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.21.111\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.111\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.111\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.111\psuser.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.111\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\18.0.1025.162\chrome_updater.exe
c:\program files (x86)\Google\Update\Download\{FDDB16D7-2E25-45C3-9933-518AEC31E55A}\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Spybot - Search & Destroy
c:\program files (x86)\Spybot - Search & Destroy\advcheck.dll
c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe
c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\120422-190211.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\120423-220402.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Fixes.120422-1735.txt
c:\programdata\Spybot - Search & Destroy\Logs\Fixes.120422-1832.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120223-2202.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1657.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1714.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1738.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1819.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1819.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.120422-1832.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.121923-2219.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.122022-1920.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\Resident.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
c:\programdata\Spybot - Search & Destroy\ProcCache.sbc
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar.zip
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar1.zip
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar2.zip
c:\programdata\Spybot - Search & Destroy\Recovery\BabylonToolbar3.zip
c:\programdata\XoftSpySE
c:\programdata\XoftSpySE\6\8B13A86E.plf
c:\programdata\XoftSpySE\6\Ignore.db
c:\programdata\XoftSpySE\6\Quarantine.db
c:\programdata\XoftSpySE\6\Stats.db
c:\windows\logo1_.exe
c:\windows\rundll16.exe
c:\windows\SysWow64\eEmpty.exe
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 17:00 . 2012-04-09 17:00 -------- d-----w- c:\users\Anett\AppData\Roaming\No Company Name
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-27 15:16 . 2012-03-27 15:16 -------- d-----w- c:\program files (x86)\MD5 Password
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\users\Anett\AppData\Roaming\No Company Name ----
.
2012-04-09 17:00 . 2012-04-09 17:00 12 ----a-w- c:\users\Anett\AppData\Roaming\No Company Name\No Client Name\No Client Internal Version\Trace Database.txt
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-24_14.17.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-24 15:22 65784 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 15:22 45330 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-11-14 15:16 . 2012-04-24 15:22 15858 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-42510566-1014113567-1088135144-1001_UserData.bin
+ 2011-11-14 15:22 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-24 15:32 . 2012-04-24 15:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-24 15:32 . 2012-04-24 15:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-04-24 14:16 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-24 15:31 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-11-14 09:25 . 2012-04-24 14:16 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
+ 2011-11-14 09:25 . 2012-04-24 15:31 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
"combofix"="c:\combofix\CF28718.3XE" [2010-11-21 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
[HKEY_USERS\S-1-5-21-42510566-1014113567-1088135144-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{76574FE3-C073-29A1-AEB2-AD11B9E08853}*]
"oafdgmpldkbdghnkmmdjmdjcobcfio"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,62,
64,6c,67,62,6c,67,00,8a
"papcijeilihpkddpohcknblnpmmiopgn"=hex:6a,61,63,63,68,62,66,6f,66,69,66,6a,64,
62,64,6c,67,62,6c,67,00,8a
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
c:\progra~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWAgent.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 17:35:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 15:35
ComboFix2.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 529 398 931 456
Po spuštění: Volných bajtů: 528 816 902 144
.
- - End Of File - - 4D8980E7A79EC9082593E1E975864028
Ten SP: Windows Defender jsem předtím odinstalovala, ale pořád se tam ukazuje.
Virustotal:
c:\windows\killproc.exe
https://www.virustotal.com/file/9f575ec ... 335283118/
c:\windows\inst_tsp.exe
https://www.virustotal.com/file/e929115 ... 335282505/
Ostatní tři soubory jsou ve Virustotal čisté.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Jestli tam máš MicroWorld e scan , odinstaluj.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\program files (x86)\Hide The IP\data\htisvc.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
to znáš??
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
KillAll::
File::
c:\windows\winsbak.reg
c:\windows\winsbak2.reg
c:\windows\killproc.exe
c:\windows\inst_tspx.exe
c:\windows\inst_tsp.exe
c:\combofix\CF28718.3XE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWAgent.exe
Folder::
c:\users\Anett\AppData\Roaming\No Company Name
c:\progra~2\COMMON~1\MICROW~1
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"=-
RegNull::
[HKEY_USERS\S-1-5-21-42510566-1014113567-1088135144-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{76574FE3-C073-29A1-AEB2-AD11B9E08853}*]
RegLock::
[HKEY_USERS\S-1-5-21-42510566-1014113567-1088135144-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{76574FE3-C073-29A1-AEB2-AD11B9E08853}*]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\program files (x86)\Hide The IP\data\htisvc.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Kód: Vybrat vše
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
to znáš??
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
-
- nováček
- Příspěvky: 29
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
ComboFix 12-04-24.02 - Anett 24.04.2012 18:56:13.3.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2643 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Anett\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\progra~2\COMMON~1\MICROW~1
c:\progra~2\COMMON~1\MICROW~1\Agent\dnslib.dll
c:\progra~2\COMMON~1\MICROW~1\Agent\ENCDEC.DLL
c:\progra~2\COMMON~1\MICROW~1\Agent\Log\Agent.log
c:\progra~2\COMMON~1\MICROW~1\Agent\Log\DNSLIB.LOG
c:\progra~2\COMMON~1\MICROW~1\Agent\MWAGENT.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\UNIAGENT.EXE
c:\progra~2\COMMON~1\MICROW~1\WGWIN\mwl.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\mwlinks.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\up.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\upq.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\wget.exe
c:\progra~2\COMMON~1\MICROW~1\WGWIN\wgwin.ini
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2525694-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2555917-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2563894-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2567053-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\WindowsXP-KB957097-x86-ENU.exe
c:\progra~2\COMMON~1\MICROW~1\WGWIN\WindowsXP-KB958644-x86-ENU.exe
c:\progra~2\COMMON~1\MICROW~1\WGWIN\WindowsXP-KB958687-x86-ENU.exe
c:\users\Anett\AppData\Roaming\No Company Name
c:\users\Anett\AppData\Roaming\No Company Name\No Client Name\No Client Internal Version\Trace Database.txt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_MWAgent
-------\Service_MWAgent
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-27 15:16 . 2012-03-27 15:16 -------- d-----w- c:\program files (x86)\MD5 Password
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-24_14.17.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-24 15:22 65784 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 15:34 45338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-11-14 15:16 . 2012-04-24 15:34 15890 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-42510566-1014113567-1088135144-1001_UserData.bin
+ 2011-11-14 15:22 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-24 17:00 . 2012-04-24 17:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-24 17:00 . 2012-04-24 17:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-04-24 14:16 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-24 16:59 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-11-14 09:25 . 2012-04-24 14:16 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
+ 2011-11-14 09:25 . 2012-04-24 16:59 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
"combofix"="c:\combofix\CF13362.3XE" [2010-11-21 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 19:03:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 17:03
ComboFix2.txt 2012-04-24 15:35
ComboFix3.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 528 895 799 296
Po spuštění: Volných bajtů: 528 573 071 360
.
- - End Of File - - 8281E4E570818A8BBF3992776F874263
NOVÝ LOG Z HJT
ComboFix 12-04-24.02 - Anett 24.04.2012 19:30:41.4.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2388 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-24 17:33 . 2012-04-24 17:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-24_14.17.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-24 15:22 65784 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 17:02 45338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-11-14 15:16 . 2012-04-24 17:02 15946 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-42510566-1014113567-1088135144-1001_UserData.bin
- 2011-11-14 15:22 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-24 17:34 . 2012-04-24 17:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-24 17:34 . 2012-04-24 17:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-04-24 14:16 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-24 17:33 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-04-24 17:34 . 2012-04-24 17:34 4876056 c:\windows\system32\FNTCACHE.DAT
- 2012-04-24 13:54 . 2012-04-24 13:54 4876056 c:\windows\system32\FNTCACHE.DAT
+ 2011-11-14 09:46 . 2012-04-24 17:33 4135214 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-12288.dat
+ 2011-11-14 09:25 . 2012-04-24 17:33 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
- 2011-11-14 09:25 . 2012-04-24 14:16 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 19:37:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 17:37
ComboFix2.txt 2012-04-24 17:03
ComboFix3.txt 2012-04-24 15:35
ComboFix4.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 529 058 492 416
Po spuštění: Volných bajtů: 528 983 269 376
.
- - End Of File - - 0BFB660157185E1BC6287A9AEA904CDD
Test na Virustotal byl čistý.
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
- NEZNÁM
LOG z aswMBR
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-24 19:42:15
-----------------------------
19:42:15.394 OS Version: Windows x64 6.1.7601 Service Pack 1
19:42:15.394 Number of processors: 4 586 0x2A07
19:42:15.394 ComputerName: PC-LENOVO UserName: Anett
19:42:18.514 Initialize success
19:42:25.749 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:42:25.749 Disk 0 Vendor: ST310005 CC6B Size: 953869MB BusType: 3
19:42:25.749 Disk 0 MBR read successfully
19:42:25.749 Disk 0 MBR scan
19:42:25.764 Disk 0 Windows 7 default MBR code
19:42:25.764 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
19:42:25.764 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 928093 MB offset 206848
19:42:25.811 Disk 0 Partition 3 00 12 Compaq diag NTFS 25675 MB offset 1900941312
19:42:25.827 Disk 0 scanning C:\windows\system32\drivers
19:42:31.521 Service scanning
19:42:41.957 Modules scanning
19:42:41.957 Disk 0 trace - called modules:
19:42:41.988 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
19:42:41.988 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80065f5060]
19:42:42.503 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800539c050]
19:42:42.503 Scan finished successfully
19:42:54.172 Disk 0 MBR has been saved successfully to "C:\Users\Anett\Desktop\MBR.dat"
19:42:54.172 The log file has been saved successfully to "C:\Users\Anett\Desktop\aswMBR.txt"
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2643 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Anett\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\progra~2\COMMON~1\MICROW~1
c:\progra~2\COMMON~1\MICROW~1\Agent\dnslib.dll
c:\progra~2\COMMON~1\MICROW~1\Agent\ENCDEC.DLL
c:\progra~2\COMMON~1\MICROW~1\Agent\Log\Agent.log
c:\progra~2\COMMON~1\MICROW~1\Agent\Log\DNSLIB.LOG
c:\progra~2\COMMON~1\MICROW~1\Agent\MWAGENT.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\MWASER.EXE
c:\progra~2\COMMON~1\MICROW~1\Agent\UNIAGENT.EXE
c:\progra~2\COMMON~1\MICROW~1\WGWIN\mwl.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\mwlinks.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\up.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\upq.txt
c:\progra~2\COMMON~1\MICROW~1\WGWIN\wget.exe
c:\progra~2\COMMON~1\MICROW~1\WGWIN\wgwin.ini
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2525694-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2555917-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2563894-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\Windows6.1-KB2567053-x64.msu
c:\progra~2\COMMON~1\MICROW~1\WGWIN\WindowsXP-KB957097-x86-ENU.exe
c:\progra~2\COMMON~1\MICROW~1\WGWIN\WindowsXP-KB958644-x86-ENU.exe
c:\progra~2\COMMON~1\MICROW~1\WGWIN\WindowsXP-KB958687-x86-ENU.exe
c:\users\Anett\AppData\Roaming\No Company Name
c:\users\Anett\AppData\Roaming\No Company Name\No Client Name\No Client Internal Version\Trace Database.txt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_MWAgent
-------\Service_MWAgent
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-27 15:16 . 2012-03-27 15:16 -------- d-----w- c:\program files (x86)\MD5 Password
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-24_14.17.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-24 15:22 65784 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 15:34 45338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-11-14 15:16 . 2012-04-24 15:34 15890 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-42510566-1014113567-1088135144-1001_UserData.bin
+ 2011-11-14 15:22 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-24 17:00 . 2012-04-24 17:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-24 17:00 . 2012-04-24 17:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-04-24 14:16 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-24 16:59 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-11-14 09:25 . 2012-04-24 14:16 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
+ 2011-11-14 09:25 . 2012-04-24 16:59 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
"combofix"="c:\combofix\CF13362.3XE" [2010-11-21 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 19:03:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 17:03
ComboFix2.txt 2012-04-24 15:35
ComboFix3.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 528 895 799 296
Po spuštění: Volných bajtů: 528 573 071 360
.
- - End Of File - - 8281E4E570818A8BBF3992776F874263
NOVÝ LOG Z HJT
ComboFix 12-04-24.02 - Anett 24.04.2012 19:30:41.4.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4077.2388 [GMT 2:00]
Spuštěný z: c:\users\Anett\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-24 do 2012-04-24 )))))))))))))))))))))))))))))))
.
.
2012-04-24 17:33 . 2012-04-24 17:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-22 14:07 . 2012-04-22 14:07 -------- d-----w- c:\program files\Defraggler
2012-04-20 12:58 . 2012-04-22 13:44 -------- d-----w- c:\users\Anett\AppData\Roaming\EPSON
2012-04-20 12:44 . 2012-04-20 12:44 -------- d-----w- c:\programdata\UDL
2012-04-20 12:42 . 2012-04-20 12:42 -------- d-----w- c:\program files\Epson Software
2012-04-17 22:03 . 2012-04-17 22:03 -------- d-----w- c:\users\Anett\creepy
2012-04-17 22:03 . 2012-04-22 13:58 -------- d-----w- c:\program files (x86)\creepy
2012-04-10 22:55 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:55 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-10 22:55 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:55 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:55 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-09 17:23 . 2012-04-09 17:23 -------- d-----w- c:\users\Anett\AppData\Roaming\Auslogics
2012-04-09 16:35 . 2012-04-09 16:35 -------- d-----w- c:\program files\ESET
2012-04-04 11:56 . 2012-04-07 22:28 -------- d-----w- c:\users\Anett\AppData\Local\PokerStars.NET
2012-04-04 11:56 . 2012-04-04 11:56 -------- d-----w- c:\program files (x86)\PokerStars.NET
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-04-02 08:08 . 2012-04-13 20:08 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-02 07:41 . 2012-04-13 20:08 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-25 17:52 . 2012-04-09 16:53 -------- d-----w- c:\program files (x86)\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 20:08 . 2011-11-14 09:56 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 17:09 . 2012-01-04 10:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-20 05:50 . 2012-03-20 05:50 4435968 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-02-24 15:36 . 2012-02-24 15:36 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2012-02-24 15:36 . 2012-02-24 15:36 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2012-02-24 15:32 . 2012-02-24 15:32 3956 ----a-w- c:\windows\winsbak.reg
2012-02-24 15:32 . 2012-02-24 15:32 143174 ----a-w- c:\windows\winsbak2.reg
2012-02-23 13:39 . 2012-02-23 13:39 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2012-02-23 13:39 . 2012-02-23 13:39 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2012-02-22 01:16 . 2012-02-24 15:33 702216 ----a-w- c:\windows\system32\mwtsp.dll
2012-02-22 01:16 . 2012-02-24 15:30 702216 ----a-w- c:\windows\SysWow64\mwtsp64.dll
2012-02-22 01:15 . 2012-02-24 15:30 629000 ----a-w- c:\windows\SysWow64\mwtsp.dll
2012-02-22 01:15 . 2012-02-24 15:31 80136 ----a-w- c:\windows\killproc.exe
2012-02-22 01:15 . 2012-02-24 15:30 232200 ----a-w- c:\windows\inst_tspx.exe
2012-02-22 01:15 . 2012-02-24 15:30 91912 ----a-w- c:\windows\inst_tsp.exe
2012-02-22 01:14 . 2012-02-24 15:33 207112 ----a-w- c:\windows\system32\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 207112 ----a-w- c:\windows\SysWow64\mwnsp64.dll
2012-02-22 01:14 . 2012-02-24 15:30 212744 ----a-w- c:\windows\SysWow64\mwnsp.dll
2012-02-22 01:14 . 2012-02-24 15:30 689928 ----a-w- c:\windows\SysWow64\eslogon.dll
2012-02-22 01:14 . 2012-02-24 15:30 1877256 ----a-w- c:\windows\SysWow64\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:33 2345224 ----a-w- c:\windows\system32\contfilt.dll
2012-02-22 01:14 . 2012-02-24 15:30 2345224 ----a-w- c:\windows\SysWow64\contf64.dll
2012-02-22 01:13 . 2012-02-24 15:30 3099912 ----a-w- c:\windows\SysWow64\ASAPSDK.DLL
2012-02-17 06:38 . 2012-03-14 08:46 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 08:46 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 08:46 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 08:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:36 . 2012-03-14 08:48 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 08:48 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-16 21:15 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{84DD5092-B915-483B-8D6E-3F622A9CD95A}\mpengine.dll
2012-02-03 04:34 . 2012-03-14 08:48 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 12:57 . 2012-02-02 12:57 808440 ----a-w- c:\windows\SysWow64\CDDBUI.dll
2012-02-02 12:57 . 2012-02-02 12:57 796152 ----a-w- c:\windows\SysWow64\CDDBControl.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-27 13:27 . 2012-01-27 13:27 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-24_14.17.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-04-24 15:22 65784 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-24 17:02 45338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-11-14 15:16 . 2012-04-24 17:02 15946 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-42510566-1014113567-1088135144-1001_UserData.bin
- 2011-11-14 15:22 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-14 15:22 . 2012-04-24 14:13 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-11-14 15:22 . 2012-04-24 14:37 81920 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-24 14:13 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-24 14:37 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-24 17:34 . 2012-04-24 17:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-24 17:34 . 2012-04-24 17:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-04-24 14:16 . 2012-04-24 14:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-04-24 14:16 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-24 17:33 379928 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-04-24 17:34 . 2012-04-24 17:34 4876056 c:\windows\system32\FNTCACHE.DAT
- 2012-04-24 13:54 . 2012-04-24 13:54 4876056 c:\windows\system32\FNTCACHE.DAT
+ 2011-11-14 09:46 . 2012-04-24 17:33 4135214 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-12288.dat
+ 2011-11-14 09:25 . 2012-04-24 17:33 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
- 2011-11-14 09:25 . 2012-04-24 14:16 21093244 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-42510566-1014113567-1088135144-1001-8192.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"CLMLServer"="c:\program files (x86)\Lenovo\Power2Go\CLMLSvc.exe" [2009-12-04 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"SetDefaultSCR"="c:\program files (x86)\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe" [2009-12-31 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 esihdrv;esihdrv;c:\users\Anett\AppData\Local\Temp\esihdrv.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AVRedirector;AVRedirector;c:\program files (x86)\Hide The IP\data\AVLib.EXE [2011-07-01 3208096]
S2 CEEBC40A-FDED-4C59-B354-939132350B01;Roxio File Backup Service;c:\program files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe [2010-08-30 96752]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - AVSoftwareHTIFirewall
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 4035152]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\users\Anett\AppData\Roaming\Mozilla\Firefox\Profiles\e7xruh55.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f5,5e,6e,eb,c9,ec,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e7,82,9e,31,bf,07,70,4c,aa,25,30,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Hide The IP\data\htisvc.exe
.
**************************************************************************
.
Celkový čas: 2012-04-24 19:37:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-24 17:37
ComboFix2.txt 2012-04-24 17:03
ComboFix3.txt 2012-04-24 15:35
ComboFix4.txt 2012-04-24 14:20
.
Před spuštěním: Volných bajtů: 529 058 492 416
Po spuštění: Volných bajtů: 528 983 269 376
.
- - End Of File - - 0BFB660157185E1BC6287A9AEA904CDD
Test na Virustotal byl čistý.
TCP: Interfaces\{41957598-A272-4B08-8A51-418486F362F2}: NameServer = 8.26.56.26,156.154.70.22
- NEZNÁM
LOG z aswMBR
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-24 19:42:15
-----------------------------
19:42:15.394 OS Version: Windows x64 6.1.7601 Service Pack 1
19:42:15.394 Number of processors: 4 586 0x2A07
19:42:15.394 ComputerName: PC-LENOVO UserName: Anett
19:42:18.514 Initialize success
19:42:25.749 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:42:25.749 Disk 0 Vendor: ST310005 CC6B Size: 953869MB BusType: 3
19:42:25.749 Disk 0 MBR read successfully
19:42:25.749 Disk 0 MBR scan
19:42:25.764 Disk 0 Windows 7 default MBR code
19:42:25.764 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
19:42:25.764 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 928093 MB offset 206848
19:42:25.811 Disk 0 Partition 3 00 12 Compaq diag NTFS 25675 MB offset 1900941312
19:42:25.827 Disk 0 scanning C:\windows\system32\drivers
19:42:31.521 Service scanning
19:42:41.957 Modules scanning
19:42:41.957 Disk 0 trace - called modules:
19:42:41.988 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
19:42:41.988 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80065f5060]
19:42:42.503 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800539c050]
19:42:42.503 Scan finished successfully
19:42:54.172 Disk 0 MBR has been saved successfully to "C:\Users\Anett\Desktop\MBR.dat"
19:42:54.172 The log file has been saved successfully to "C:\Users\Anett\Desktop\aswMBR.txt"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Místo HJT si dala 2x Combofix...
Stáhni si rkill
a spusť ho . Spustí se sken .Po skenu se program sám ukončí.
Pozn.: NERESTARTUJ PC !
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si rkill
a spusť ho . Spustí se sken .Po skenu se program sám ukončí.
Pozn.: NERESTARTUJ PC !
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
KillAll::
File::
c:\windows\winsbak.reg
c:\windows\winsbak2.reg
c:\windows\killproc.exe
c:\windows\inst_tspx.exe
c:\windows\inst_tsp.exe
c:\combofix\CF28718.3XE
RegNull::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 81 hostů