Díky za radu

Taky jsem přišel proč se to seklo na 6 fázi páč sem zavřel víko ntb
ComboFix 12-05-03.02 - Woytman 04.05.2012 23:53:37.2.4 - x64 MINIMAL
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3767.2484 [GMT 2:00]
Spuštěný z: c:\users\Woytman\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-04-04 do 2012-05-04 )))))))))))))))))))))))))))))))
.
.
2012-05-04 22:00 . 2012-05-04 22:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-04 20:24 . 2012-05-04 20:24 -------- d-----w- c:\program files (x86)\MegaDev
2012-05-04 17:45 . 2012-05-04 17:45 -------- d-----w- c:\program files (x86)\Rebellion
2012-05-03 21:02 . 2012-05-03 21:02 -------- d-----w- c:\program files (x86)\City Interactive
2012-05-02 20:13 . 2012-05-02 20:13 -------- d-----w- c:\program files (x86)\Milestone
2012-05-02 19:54 . 2012-05-02 19:55 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2012-05-02 19:03 . 2012-05-02 19:03 -------- d-----w- c:\programdata\Malwarebytes
2012-05-02 19:03 . 2012-05-02 19:10 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-05-02 19:03 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-29 13:38 . 2012-04-29 13:38 -------- d-----w- c:\program files (x86)\NFSNation
2012-04-28 22:09 . 2012-04-28 22:09 -------- d-sh--w- c:\programdata\DSS
2012-04-28 22:09 . 2012-04-28 22:09 -------- d-----w- c:\programdata\Codemasters
2012-04-28 21:53 . 2012-04-28 21:53 -------- d-----w- c:\programdata\Ubisoft
2012-04-28 16:21 . 2010-09-22 11:12 19087360 ----a-w- c:\windows\SysWow64\mkl_blueripple.dll
2012-04-28 16:21 . 2012-04-28 16:21 -------- d-----w- c:\program files (x86)\BRS
2012-04-28 16:21 . 2011-03-19 13:16 1417216 ----a-w- c:\windows\SysWow64\rapture3d_oal.dll
2012-04-28 16:07 . 2012-04-28 16:07 -------- d-----w- c:\program files (x86)\Codemasters
2012-04-28 11:30 . 2012-04-28 11:30 -------- d-----w- c:\windows\SysWow64\QuickTime
2012-04-28 11:30 . 2012-04-28 11:30 -------- d-----w- c:\program files (x86)\QuickTime
2012-04-28 11:30 . 2012-04-28 11:30 -------- d-----w- c:\program files (x86)\Common Files\TechSmith Shared
2012-04-28 11:30 . 2012-04-28 11:30 -------- d-----w- c:\programdata\TechSmith
2012-04-28 11:30 . 2012-04-28 11:30 -------- d-----w- c:\program files (x86)\TechSmith
2012-04-28 10:53 . 2012-05-03 19:50 -------- d-----w- c:\program files (x86)\SoundSpectrum
2012-04-28 09:33 . 2012-04-28 09:33 -------- d-----w- c:\program files (x86)\Bethesda Softworks
2012-04-28 08:36 . 2012-04-28 08:36 -------- d-----w- c:\programdata\Research In Motion
2012-04-28 08:33 . 2011-07-20 12:58 44032 ----a-w- c:\windows\system32\drivers\RimSerial_AMD64.sys
2012-04-28 08:33 . 2012-04-28 08:35 -------- d-----w- c:\program files (x86)\Research In Motion
2012-04-28 07:59 . 2012-04-28 07:59 -------- d-----w- C:\TopCD
2012-04-28 07:50 . 2012-05-02 18:53 -------- d-----w- c:\program files\Emergency 4
2012-04-28 07:43 . 2012-04-28 07:43 -------- d-----w- c:\program files (x86)\Electronic Arts
2012-04-28 07:38 . 2012-04-28 07:38 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-04-28 07:38 . 2012-04-28 16:21 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-04-28 07:38 . 2012-04-28 16:21 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-04-28 07:38 . 2012-04-28 16:21 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-04-28 07:38 . 2012-04-28 16:21 -------- d-----w- c:\program files (x86)\OpenAL
2012-04-28 07:38 . 2012-04-28 16:21 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-04-28 07:37 . 2012-04-28 07:37 -------- d-----w- c:\program files (x86)\NeutronGames
2012-04-28 07:19 . 2012-04-28 07:19 -------- d-----w- c:\program files (x86)\EA Games
2012-04-28 07:16 . 2012-05-03 17:41 183112 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-04-28 07:16 . 2012-04-28 23:14 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-04-26 21:44 . 2012-05-02 18:57 -------- d-----w- c:\program files (x86)\Yontoo
2012-04-26 21:44 . 2012-04-26 21:44 -------- d-----w- c:\programdata\Tarma Installer
2012-04-25 09:10 . 2012-04-25 09:10 -------- d-----w- c:\program files (x86)\Sidhe
2012-04-24 20:58 . 2012-04-28 08:35 -------- d-----w- c:\program files (x86)\Common Files\Research In Motion
2012-04-24 20:31 . 2012-05-03 19:54 -------- d-----w- c:\program files (x86)\1ClickDownload
2012-04-23 23:56 . 2012-04-23 23:56 -------- d-----w- C:\01ff393ab0a90b3deb98
2012-04-23 15:28 . 2012-04-28 06:52 -------- d-----w- c:\program files\Deep Silver
2012-04-23 13:25 . 2009-10-24 19:15 1332224 ----a-w- c:\windows\SysWow64\SYNSOEMU.DLL
2012-04-23 12:40 . 2012-04-23 12:40 -------- d-----w- c:\program files\CCleaner
2012-04-22 20:15 . 1999-12-17 08:13 86016 ----a-w- c:\windows\unvise32.exe
2012-04-22 19:58 . 2012-04-22 19:58 -------- dc-h--w- c:\programdata\{13A9B825-42CB-4973-913D-2194B5A4CF94}
2012-04-22 19:55 . 2012-04-22 19:55 -------- d-----w- c:\program files\Common Files\Digidesign
2012-04-22 19:53 . 2012-04-22 19:55 -------- d-----w- c:\program files (x86)\Native Instruments
2012-04-21 17:09 . 2012-04-21 17:09 -------- d-----w- C:\asdasf
2012-04-21 15:27 . 2012-04-21 15:27 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-21 15:27 . 2012-04-21 15:27 -------- d-----w- c:\windows\system32\Wat
2012-04-20 22:29 . 2012-04-20 22:29 -------- d-----w- c:\program files (x86)\MSXML 4.0
2012-04-20 22:24 . 2012-03-06 06:53 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-20 22:24 . 2012-03-06 05:59 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-04-20 22:24 . 2012-03-06 05:59 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-04-20 22:14 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-20 22:14 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-20 22:14 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-20 22:14 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-20 22:14 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-20 22:14 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-20 22:14 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-20 21:34 . 2012-04-21 21:25 -------- d-----w- C:\sss
2012-04-20 21:22 . 2012-04-23 15:41 -------- d-----w- C:\compilador v2
2012-04-20 12:29 . 2012-04-20 12:29 -------- d-----w- c:\program files (x86)\Square Enix
2012-04-20 12:06 . 2012-04-24 14:20 -------- d-----w- c:\program files (x86)\Battlefield 3
2012-04-20 11:58 . 2012-04-20 11:58 -------- d-----w- c:\program files (x86)\Sega
2012-04-20 11:49 . 2012-04-28 07:02 -------- d-----w- c:\program files (x86)\Ubisoft
2012-04-19 18:57 . 2012-04-19 18:57 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-04-19 18:40 . 2012-04-20 12:02 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-04-19 18:40 . 2012-04-19 18:40 -------- d-----w- c:\windows\SysWow64\xlive
2012-04-19 17:59 . 2012-04-19 20:56 -------- d-----w- c:\program files (x86)\Rockstar Games
2012-04-19 16:45 . 2012-04-19 16:46 -------- d-----w- c:\program files\Microsoft Xbox 360 Accessories
2012-04-19 16:41 . 2007-01-24 13:27 393576 ----a-w- c:\windows\system32\xactengine2_6.dll
2012-04-19 16:41 . 2007-01-24 13:27 255848 ----a-w- c:\windows\SysWow64\xactengine2_6.dll
2012-04-19 16:41 . 2007-03-05 10:42 15128 ----a-w- c:\windows\SysWow64\x3daudio1_1.dll
2012-04-19 16:41 . 2007-03-05 10:42 17688 ----a-w- c:\windows\system32\x3daudio1_1.dll
2012-04-19 16:22 . 2012-04-19 16:40 -------- d-----w- c:\program files (x86)\Mass Effect 3
2012-04-19 14:35 . 2012-04-19 14:35 -------- d-----w- c:\program files (x86)\2K Games
2012-04-18 20:59 . 2012-04-18 21:01 -------- d-----w- c:\program files (x86)\Valve
2012-04-18 20:47 . 2012-04-18 20:47 -------- d-----w- c:\program files\Common Files\Native Instruments
2012-04-18 20:47 . 2012-04-22 19:57 -------- d-----w- c:\program files (x86)\Common Files\Native Instruments
2012-04-18 20:47 . 2012-04-18 20:47 -------- d-----w- c:\program files (x86)\Common Files\Digidesign
2012-04-18 20:47 . 2012-04-18 20:47 -------- dc-h--w- c:\programdata\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
2012-04-18 20:47 . 2012-04-22 19:57 -------- d-----w- c:\program files\Native Instruments
2012-04-18 20:47 . 2012-04-18 20:47 -------- d-----w- c:\programdata\Native Instruments
2012-04-18 20:46 . 2012-04-18 20:46 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-04-18 20:46 . 2012-04-18 20:46 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2012-04-18 20:21 . 2012-04-18 20:21 -------- d-----w- c:\program files (x86)\ASIO4ALL v2
2012-04-18 20:21 . 2012-05-02 18:30 -------- d-----w- c:\program files (x86)\VstPlugins
2012-04-18 20:21 . 2006-06-20 08:56 225280 ----a-w- c:\windows\SysWow64\rewire.dll
2012-04-18 20:21 . 2009-08-02 20:09 1554944 ----a-w- c:\windows\SysWow64\vorbis.acm
2012-04-18 20:21 . 2012-04-18 20:21 -------- d-----w- c:\program files (x86)\Outsim
2012-04-18 20:18 . 2012-04-18 20:41 -------- d-----w- c:\program files (x86)\Image-Line
2012-04-18 20:11 . 2012-04-18 20:16 -------- d-----w- c:\program files (x86)\FIFA 12
2012-04-18 17:13 . 2009-07-10 10:43 1589248 ----a-w- c:\windows\SysWow64\libmysql_d.dll
2012-04-18 17:13 . 2012-04-18 17:15 -------- d-----w- c:\program files (x86)\PremiumSoft
2012-04-18 17:13 . 2012-04-18 17:13 -------- d-----w- c:\program files (x86)\TeamViewer
2012-04-18 17:13 . 2012-04-18 17:13 -------- d-----w- c:\program files (x86)\UltraVNC
2012-04-18 17:12 . 2012-04-18 17:12 -------- d-----w- c:\program files (x86)\PSPad editor
2012-04-18 17:10 . 2012-04-18 17:10 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-04-18 17:10 . 2012-04-18 17:10 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-04-18 16:48 . 2012-04-18 16:52 -------- d-----w- c:\program files (x86)\Google
2012-04-18 16:47 . 2012-04-18 17:16 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-04-18 04:26 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-04-18 04:26 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-04-18 04:26 . 2011-08-27 05:37 861696 ----a-w- c:\windows\system32\oleaut32.dll
2012-04-18 04:26 . 2011-08-27 05:37 331776 ----a-w- c:\windows\system32\oleacc.dll
2012-04-18 04:26 . 2011-08-27 04:26 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2012-04-18 04:26 . 2011-08-27 04:26 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2012-04-18 04:26 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2012-04-18 04:26 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-04-18 04:26 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2012-04-18 04:26 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-04-18 04:26 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-04-18 04:26 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-04-17 16:42 . 2012-04-24 13:38 -------- d-----w- c:\users\UpdatusUser
2012-04-17 16:42 . 2012-02-29 21:00 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-04-17 16:42 . 2012-02-29 21:00 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-04-17 16:42 . 2012-02-29 20:59 889664 ----a-w- c:\windows\system32\nvvsvc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-04 20:31 . 2012-01-20 11:59 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-06 19:11 . 2011-03-29 02:36 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-04-06 18:26 . 2012-04-06 18:26 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\qwavedrv.sys.mui
2012-04-06 18:26 . 2012-04-06 18:26 5632 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\ndiscap.sys.mui
2012-04-06 18:26 . 2012-04-06 18:26 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\scfilter.sys.mui
2012-04-06 18:26 . 2012-04-06 18:26 50176 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\tcpip.sys.mui
2012-04-06 18:26 . 2012-04-06 18:26 27136 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\bfe.dll.mui
2012-04-06 18:26 . 2012-04-06 18:26 15360 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\pacer.sys.mui
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" [2010-06-28 263936]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-04-13 284696]
"RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-11-02 90448]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20120413.001\BHDrvx64.sys [2012-04-02 1160824]
R1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1300000.080\ccSetx64.sys [x]
R1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20120504.001\IDSvia64.sys [2012-04-28 488568]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1300000.080\Ironx64.SYS [x]
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\NISx64\1300000.080\SYMNETS.SYS [x]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
R2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104]
R2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2011-01-05 867712]
R2 GREGService;GREGService;c:\program files (x86)\Packard Bell\Registration\GREGsvc.exe [2011-05-30 36456]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-18 136176]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
R2 Live Updater Service;Live Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2011-04-22 244624]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.0.0.128\ccSvcHst.exe [2011-05-24 138760]
R2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2010-06-28 255744]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 257696]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-04-17 138360]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-18 136176]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1300000.080\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1300000.080\SYMEFA64.SYS [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-05-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 20:31]
.
2012-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-18 16:48]
.
2012-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-18 16:48]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-03-13 617120]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-03-13 379552]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-29 497648]
"Acer ePower Management"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerTray.exe" [2011-01-05 860040]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-10 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-10 392984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-10 417560]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 825184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
TCP: DhcpNameServer = 82.100.3.1 62.240.162.158
FF - ProfilePath - c:\users\Woytman\AppData\Roaming\Mozilla\Firefox\Profiles\cwcfcwac.default\
FF - user.js: extentions.y2layers.installId - 7ba8dc3a-5f63-489b-bc70-512831edd56e
FF - user.js: extentions.y2layers.defaultEnableAppsList - bestvideodownloader,ezLooker,pagerage,buzzdock,toprelatedtopics,twittube
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-Driver Genius - (no file)
Toolbar-Locked - (no file)
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.0.0.128\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.0.0.128\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2000845088-3818977652-3785840965-1002\Software\SecuROM\License information*]
"datasecu"=hex:c1,00,79,9d,38,b8,93,90,b3,e2,5b,43,4f,88,71,6d,0f,3e,d7,82,90,
7c,15,f2,0c,ec,f1,d4,11,ed,7c,e8,d4,37,d3,6f,55,7c,64,f8,fb,a6,33,eb,4e,ee,\
"rkeysecu"=hex:00,fc,a1,18,ef,68,ed,be,9c,c1,05,4f,a4,be,13,59
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-05-05 00:02:42
ComboFix-quarantined-files.txt 2012-05-04 22:02
.
Před spuštěním: Volných bajtů: 150 392 705 024
Po spuštění: Volných bajtů: 150 142 582 784
.
- - End Of File - - 1DE4D79C3E47ADB19442CFCA7DFC9679