ComboFix 13-07-22.01 - Jitka 24.07.2013 15:31:06.9.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3068.992 [GMT 2:00]
Spuštěný z: c:\users\Jitka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jitka\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3416734063-1635780789-2204153844-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3416734063-1635780789-2204153844-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.21.153\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.153\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.153\psuser.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.153\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\28.0.1500.72\28.0.1500.72_28.0.1500.71_chrome_updater.exe
c:\program files (x86)\Google\Update\Download\{74AF07D8-FB8F-4D51-8AC7-927721D56EBB}\0.0.0.0\GoogleEarth-Win-Bundle-7.0.3.8542.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
C:\TDSSKiller_Quarantine
c:\tdsskiller_quarantine\19.07.2013_22.38.09\zasubsys0000\file0000\object.ini
c:\tdsskiller_quarantine\19.07.2013_22.38.09\zasubsys0000\file0000\tsk0000.dta
c:\tdsskiller_quarantine\19.07.2013_22.38.09\zasubsys0000\file0000\tsk0000.ini
c:\tdsskiller_quarantine\19.07.2013_22.38.09\zasubsys0000\object.ini
c:\tdsskiller_quarantine\19.07.2013_22.38.09\zasubsys0000\zafs0000\tsk0000.dta
c:\tdsskiller_quarantine\19.07.2013_22.38.09\zasubsys0000\zafs0000\tsk0000.ini
c:\users\Jitka\AppData\Local\Facebook\Update
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\FacebookCrashHandler.exe
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdate.exe
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\FacebookUpdateHelper.msi
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ar.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bg.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_bn.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ca.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_cs.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_da.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_de.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_el.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en-GB.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_en.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es-419.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_es.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_et.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fa.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fi.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fil.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_fr.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_gu.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hi.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hr.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_hu.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_id.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_is.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_it.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_iw.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ja.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_kn.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ko.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lt.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_lv.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ml.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_mr.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ms.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_nl.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_no.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_or.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pl.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-BR.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_pt-PT.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ro.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ru.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sk.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sl.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sr.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_sv.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ta.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_te.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_th.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_tr.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_uk.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_ur.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_vi.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-CN.dll
c:\users\Jitka\AppData\Local\Facebook\Update\1.2.205.0\goopdateres_zh-TW.dll
c:\users\Jitka\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
c:\windows\system32\Services.exe . . . je infikován!!
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-06-24 do 2013-07-24 )))))))))))))))))))))))))))))))
.
.
2013-07-24 14:43 . 2013-07-24 14:43 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-07-24 14:43 . 2013-07-24 14:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-24 14:43 . 2013-07-24 14:43 -------- d-----w- c:\users\AppData\AppData\Local\temp
2013-07-24 11:14 . 2013-05-29 05:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-07-24 11:03 . 2012-12-16 13:31 48128 ----a-w- c:\windows\system32\atmlib.dll
2013-07-24 11:03 . 2012-12-16 13:12 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-07-24 11:03 . 2012-12-16 11:08 368128 ----a-w- c:\windows\system32\atmfd.dll
2013-07-24 11:03 . 2012-12-16 10:50 293376 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-07-23 16:00 . 2013-02-12 02:18 19456 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-07-23 16:00 . 2013-05-08 04:50 1423720 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-07-23 16:00 . 2012-05-11 15:57 623616 ----a-w- c:\windows\SysWow64\localspl.dll
2013-07-23 16:00 . 2012-05-11 16:34 788480 ----a-w- c:\windows\system32\localspl.dll
2013-07-23 16:00 . 2012-06-08 17:59 12899840 ----a-w- c:\windows\system32\shell32.dll
2013-07-23 16:00 . 2012-09-25 16:31 91648 ----a-w- c:\windows\system32\synceng.dll
2013-07-23 16:00 . 2012-09-25 16:19 75776 ----a-w- c:\windows\SysWow64\synceng.dll
2013-07-23 16:00 . 2012-05-01 14:29 209920 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2013-07-23 16:00 . 2012-06-05 16:22 974848 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2013-07-23 16:00 . 2012-06-05 16:47 708608 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2013-07-23 16:00 . 2013-03-03 19:13 1513320 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-07-23 15:57 . 2012-09-28 16:34 1210368 ----a-w- c:\windows\system32\kernel32.dll
2013-07-23 15:56 . 2012-08-24 16:07 218624 ----a-w- c:\windows\system32\wintrust.dll
2013-07-23 15:56 . 2012-08-24 15:53 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-07-23 15:56 . 2012-08-21 11:50 267648 ----a-w- c:\windows\system32\drivers\volsnap.sys
2013-07-23 15:56 . 2013-03-11 13:33 4691304 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-23 15:56 . 2013-03-09 01:48 75264 ----a-w- c:\windows\system32\smss.exe
2013-07-23 15:56 . 2013-03-09 04:16 85504 ----a-w- c:\windows\system32\csrsrv.dll
2013-07-23 15:56 . 2013-05-08 04:18 1706496 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-23 15:56 . 2013-05-08 04:04 1548288 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-23 15:56 . 2012-06-04 15:29 516480 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-07-23 15:56 . 2012-06-02 00:22 347136 ----a-w- c:\windows\system32\schannel.dll
2013-07-23 15:56 . 2012-06-02 00:04 278528 ----a-w- c:\windows\SysWow64\schannel.dll
2013-07-23 15:56 . 2012-06-02 00:05 77312 ----a-w- c:\windows\SysWow64\secur32.dll
2013-07-23 15:55 . 2013-03-08 04:18 451072 ----a-w- c:\windows\system32\winsrv.dll
2013-07-23 15:55 . 2012-11-22 04:22 456192 ----a-w- c:\windows\system32\shlwapi.dll
2013-07-23 15:55 . 2012-11-02 10:47 1869824 ----a-w- c:\windows\system32\msxml3.dll
2013-07-23 15:55 . 2012-11-02 10:47 1794560 ----a-w- c:\windows\system32\msxml6.dll
2013-07-23 15:55 . 2012-11-02 10:19 1400832 ----a-w- c:\windows\SysWow64\msxml6.dll
2013-07-23 15:55 . 2012-11-02 10:19 1248768 ----a-w- c:\windows\SysWow64\msxml3.dll
2013-07-23 15:55 . 2012-06-29 16:20 648192 ----a-w- c:\windows\system32\netapi32.dll
2013-07-23 15:55 . 2012-11-08 04:26 1570816 ----a-w- c:\windows\system32\quartz.dll
2013-07-23 15:55 . 2012-11-08 03:48 1314816 ----a-w- c:\windows\SysWow64\quartz.dll
2013-07-23 15:54 . 2013-03-08 04:17 2425344 ----a-w- c:\windows\system32\mstscax.dll
2013-07-23 15:54 . 2013-03-08 03:52 2067968 ----a-w- c:\windows\SysWow64\mstscax.dll
2013-07-23 15:54 . 2013-06-04 02:03 2775040 ----a-w- c:\windows\system32\win32k.sys
2013-07-23 15:54 . 2013-05-02 04:16 686080 ----a-w- c:\windows\system32\win32spl.dll
2013-07-23 15:54 . 2013-05-02 04:04 443904 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-07-23 15:54 . 2013-05-02 04:03 37376 ----a-w- c:\windows\SysWow64\printcom.dll
2013-07-23 15:54 . 2012-11-13 01:45 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-23 15:54 . 2012-11-13 01:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-07-23 15:31 . 2013-07-15 01:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6297C16D-39EA-4AF2-BDF2-2F1AE4F832E8}\mpengine.dll
2013-07-23 15:29 . 2012-11-02 10:45 477696 ----a-w- c:\windows\system32\dpnet.dll
2013-07-23 15:29 . 2012-11-02 10:45 68096 ----a-w- c:\windows\system32\dpnathlp.dll
2013-07-23 15:29 . 2012-11-02 10:18 376320 ----a-w- c:\windows\SysWow64\dpnet.dll
2013-07-23 15:29 . 2012-11-02 08:59 26112 ----a-w- c:\windows\system32\dpnsvr.exe
2013-07-23 15:29 . 2012-11-02 08:26 23040 ----a-w- c:\windows\SysWow64\dpnsvr.exe
2013-07-19 18:51 . 2013-07-19 18:51 -------- d-----w- c:\windows\ERUNT
2013-07-19 18:19 . 2013-07-19 18:19 -------- d-----w- c:\users\Jitka\AppData\Local\ATI
2013-07-19 18:18 . 2013-07-20 15:02 -------- d-----w- c:\users\Jitka\AppData\Local\Adobe
2013-07-19 18:13 . 2013-07-19 18:14 1357 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-18 20:46 . 2013-07-18 20:46 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-07-18 20:45 . 2013-07-18 20:45 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-18 17:37 . 2013-07-18 17:44 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-07-18 17:37 . 2013-07-18 17:44 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 16:56 . 2013-06-27 17:46 -------- d-----w- c:\program files (x86)\Metro Last Light
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-19 20:56 . 2011-07-23 14:32 384512 ----a-w- c:\windows\system32\services.exe
2013-07-18 20:45 . 2012-12-01 18:36 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-07-18 20:45 . 2010-05-05 10:29 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-23 22:41 . 2006-11-02 12:35 78185248 ----a-w- c:\windows\system32\mrt.exe
2013-05-15 09:50 . 2010-06-24 09:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-02 00:06 . 2009-11-04 15:51 278800 ------w- c:\windows\system32\MpSigStub.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2013-07-19 . E2D076F2C1239AA6C7412BA6B8B1DE4E . 384512 . . [6.0.6000.16386] .. c:\windows\system32\services.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"PC Suite Tray"="c:\program files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" [2011-06-16 1500160]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-16 641704]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-15 152392]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"RequireSignedAppInit_DLLs"=0 (0x0)
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe"
.
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAu64.sys;c:\windows\SYSNATIVE\drivers\AESTAu64.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-07-13 12:20 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-18 17:44]
.
2013-07-24 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2013-03-07 12:10]
.
2012-04-07 c:\windows\Tasks\HPCeeScheduleForJitka.job
- c:\program files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2009-02-23 10:34]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 4035152]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-03-17 1128448]
"SmartMenu"="c:\program files (x86)\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [BU]
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.seznam.cz/mStart Page =
hxxp://www.google.comIE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.100.100
DPF: Garmin Communicator Plug-In -
hxxps://static.garmincdn.com/gcp/ie/4.0 ... rol_32.CABCLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-SP_4e24eecb - c:\program files (x86)\WebSearch\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3416734063-1635780789-2204153844-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BFD9DAB5-E315-D7B6-CF1A-175F784DE2E0}*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3416734063-1635780789-2204153844-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:00,79,f7,ed,9e,9b,01,f0,ad,44,4a,61,bb,11,ff,80,9f,ae,12,30,11,84,ef,
d0,d6,e6,4b,bc,9f,d4,d0,30,aa,fa,80,c4,b0,14,d4,1c,ff,87,5c,c0,40,e6,c1,88,\
"??"=hex:69,3e,43,58,9f,64,ba,75,fe,6b,77,07,2a,78,dd,74
.
[HKEY_USERS\S-1-5-21-3416734063-1635780789-2204153844-1000\Software\SecuROM\License information*]
"datasecu"=hex:08,11,84,d8,1e,31,0b,6b,fd,9a,92,d1,28,5d,df,b5,8d,63,4d,58,a0,
ac,08,84,e8,f4,62,f3,df,39,16,d0,ab,8e,34,be,d5,cf,df,fa,72,d6,59,48,e5,1e,\
"rkeysecu"=hex:e3,09,90,45,be,37,09,12,f0,16,4f,d2,31,0c,84,36
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{84d4e968-0688-4b4d-9659-fb4c4e611232}\Implemented Categories\{71B2D918-2983-47B3-8337-9BEA15F184DA}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\JSXFile\shell\Edit]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\JSXFile\shell\Open]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Photoshop.Image.10\protocol\StdFileEditing\server]
@DACL=(02 0000)
@="c:\\Program Files (x86)\\Adobe\\Adobe Photoshop CS3\\Photoshop.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{004BB91A-98DA-406F-BBBF-7A9F122A3AC2}\1.0\0\win32]
@DACL=(02 0000)
@="c:\\Program Files (x86)\\Common Files\\Adobe\\Linguistics\\Providers\\Plugins\\WRLiloPlugin1.0\\WRLiloPlugin.dll"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\DigitalPersona\Bin\DpHostW.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\ESET\ESET Smart Security\x86\ekrn.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\SMINST\BLService.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
c:\program files (x86)\PC Connectivity Solution\ServiceLayer.exe
c:\program files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
.
**************************************************************************
.
Celkový čas: 2013-07-24 17:01:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-07-24 15:01
ComboFix2.txt 2013-07-23 11:26
.
Před spuštěním: Volných bajtů: 26 848 051 200
Po spuštění: Volných bajtů: 25 531 158 528
.
- - End Of File - - 533C60DC575D493A0C04FA635E73F6F1
588AE8F0C685C02BA11F30D9CD7E61A0