Prosím o kontrolu mého Aceru +

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Martinor
Level 3
Level 3
Příspěvky: 437
Registrován: listopad 06
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu mého Aceru +

Příspěvekod Martinor » 13 pro 2010 16:47

ComboFix 10-12-12.03 - Martinor 13.12.2010 11:41:40.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3764.2772 [GMT 1:00]
Spuštěný z: c:\users\Martinor\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Martinor\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FILE ::
"c:\program files (x86)\uTorrentBar\tbuTor.dll"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CPUZ131
-------\Service_cpuz131


((((((((((((((((((((((((( Soubory vytvořené od 2010-11-13 do 2010-12-13 )))))))))))))))))))))))))))))))
.

2010-12-12 21:02 . 2010-12-13 10:47 -------- d-----w- c:\program files (x86)\uTorrent
2010-12-09 21:27 . 2010-12-09 21:27 -------- d-----w- C:\games
2010-12-09 16:40 . 2010-11-29 16:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2010-12-09 16:40 . 2010-12-09 16:40 -------- d-----w- c:\programdata\Malwarebytes
2010-12-09 16:40 . 2010-12-09 16:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-12-09 16:40 . 2010-11-29 16:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-07 14:02 . 2010-12-07 14:14 -------- d-----w- c:\program files (x86)\TrackMania Sunrise
2010-12-06 21:18 . 2010-12-06 21:18 -------- d-----w- c:\programdata\Nokia
2010-12-06 21:18 . 2010-12-06 21:18 -------- d-----w- c:\program files\DIFX
2010-12-06 21:18 . 2010-12-11 17:38 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-06 21:17 . 2010-02-26 13:33 69120 ----a-w- c:\windows\system32\nmwcdclsx64.dll
2010-12-06 21:14 . 2010-12-06 21:14 -------- d-----w- c:\programdata\Installations
2010-12-06 20:52 . 2010-12-06 20:52 -------- d-----w- c:\program files (x86)\Mio Technology
2010-12-06 08:35 . 2010-12-06 08:35 86016 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2010-12-06 08:35 . 2010-12-06 08:35 262144 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2010-12-06 08:33 . 2004-10-25 19:02 21664 ----a-w- c:\windows\SysWow64\drivers\Entech.sys
2010-12-06 08:33 . 2004-06-22 14:44 5632 ----a-w- c:\windows\SysWow64\drivers\Entech64.sys
2010-12-06 08:33 . 2001-11-19 18:05 3972 ----a-w- c:\windows\SysWow64\drivers\PciBus.sys
2010-12-06 08:33 . 2010-12-06 08:33 -------- d-----w- c:\windows\SysWow64\Futuremark
2010-12-06 08:31 . 2010-12-06 08:31 -------- d-----w- c:\program files (x86)\Futuremark
2010-12-03 13:24 . 2010-12-03 13:24 -------- dc-h--w- c:\programdata\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2010-12-02 18:10 . 2010-12-02 18:29 -------- d-----w- c:\programdata\AVerTV
2010-12-02 18:09 . 2010-06-18 20:41 106496 ----a-w- c:\windows\SysWow64\CardID.dll
2010-12-02 18:09 . 2007-02-08 20:09 49152 ----a-w- c:\windows\SysWow64\AVerIO.dll
2010-12-02 18:09 . 2005-04-29 02:08 3456 ----a-w- c:\windows\SysWow64\AVerIO.sys
2010-12-02 18:09 . 2009-10-13 16:24 606208 ----a-w- c:\windows\SysWow64\sptlib21.dll
2010-12-02 18:09 . 2009-09-04 22:47 135168 ----a-w- c:\windows\SysWow64\sptlib12.dll
2010-12-02 18:09 . 2009-09-04 06:25 311296 ----a-w- c:\windows\SysWow64\sptlib01.dll
2010-11-29 18:05 . 2010-11-29 18:05 -------- d-----w- c:\program files (x86)\rajce
2010-11-29 16:39 . 2010-11-29 16:39 -------- d-----w- c:\windows\Sun
2010-11-29 16:39 . 2010-11-29 16:39 -------- d-----w- c:\program files (x86)\Common Files\Java
2010-11-29 16:38 . 2010-11-29 16:38 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-11-29 16:38 . 2010-11-29 16:38 -------- d-----w- c:\program files (x86)\Java
2010-11-29 16:01 . 2010-11-29 16:01 -------- d-----r- C:\Certificates
2010-11-28 13:36 . 2010-07-07 06:55 545 ----a-w- c:\windows\UC.PIF
2010-11-28 13:36 . 2010-07-07 06:55 545 ----a-w- c:\windows\RAR.PIF
2010-11-28 13:36 . 2010-07-07 06:55 545 ----a-w- c:\windows\PKZIP.PIF
2010-11-28 13:36 . 2010-07-07 06:55 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-11-28 13:36 . 2010-07-07 06:55 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-11-28 13:36 . 2010-07-07 06:55 545 ----a-w- c:\windows\LHA.PIF
2010-11-28 13:36 . 2010-07-07 06:55 545 ----a-w- c:\windows\ARJ.PIF
2010-11-28 13:36 . 2010-11-28 13:36 -------- d-----w- C:\totalcmd
2010-11-27 16:51 . 2010-11-27 16:51 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2010-11-27 16:22 . 2010-11-27 16:22 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2010-11-27 16:20 . 2010-11-27 16:20 -------- d-----w- c:\windows\SysWow64\xlive
2010-11-27 16:20 . 2010-11-27 16:20 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2010-11-27 14:33 . 2010-11-27 16:02 -------- d-----w- c:\program files (x86)\Rockstar Games
2010-11-27 14:17 . 2010-11-27 14:17 -------- d-----w- c:\programdata\Electronic Arts
2010-11-27 12:54 . 2010-11-30 18:53 269128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2010-11-26 23:17 . 2010-11-26 23:17 -------- d-----w- c:\program files (x86)\Aspyr
2010-11-26 22:16 . 2008-04-28 11:03 47160 ----a-w- c:\windows\system32\drivers\AmdTools64.sys
2010-11-26 22:16 . 2010-11-26 22:17 -------- d-----w- c:\program files (x86)\AMD GPU Clock Tool
2010-11-26 22:02 . 2010-11-26 22:02 -------- d-----w- c:\program files\ATI Technologies
2010-11-26 22:01 . 2010-11-26 22:01 -------- d-----w- C:\ATI
2010-11-26 21:49 . 2010-11-26 21:49 -------- d-----w- c:\program files (x86)\OCCT
2010-11-26 07:55 . 2010-12-11 17:38 -------- d-----w- c:\program files (x86)\Prime95
2010-11-26 07:48 . 2010-12-06 20:56 -------- d-----w- c:\program files (x86)\SetFSB
2010-11-26 07:12 . 2010-07-09 12:19 21480 ----a-w- c:\windows\system32\drivers\cpuz134_x64.sys
2010-11-26 06:35 . 2010-11-26 06:35 -------- d-----w- C:\Fraps
2010-11-25 19:43 . 2010-11-25 19:43 -------- d-----w- c:\program files (x86)\Common Files\Skype
2010-11-25 19:43 . 2010-12-11 17:38 -------- d-----r- c:\program files (x86)\Skype
2010-11-25 19:43 . 2010-11-25 19:43 -------- d-----w- c:\programdata\Skype
2010-11-25 10:46 . 2010-11-25 10:46 29536 ----a-w- c:\windows\SysWow64\drivers\TVicHW32.sys
2010-11-25 10:46 . 2010-11-25 10:46 21200 ----a-w- c:\windows\system32\drivers\TVicHW32.sys
2010-11-25 08:06 . 2010-11-25 08:06 -------- d-----w- c:\program files (x86)\THQ
2010-11-25 05:50 . 2010-11-25 05:50 -------- d--h--w- c:\programdata\CanonBJ
2010-11-25 05:50 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL
2010-11-24 09:00 . 2010-11-24 09:00 -------- d-----w- c:\programdata\Solidshield
2010-11-24 08:42 . 2010-11-24 08:42 2434856 ----a-w- c:\windows\SysWow64\pbsvc_bc2.exe
2010-11-24 08:22 . 2010-12-03 13:19 -------- d-----w- c:\program files (x86)\Electronic Arts
2010-11-24 08:09 . 2010-10-19 08:47 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-24 08:09 . 2010-10-19 08:10 7680 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2010-11-24 07:57 . 2010-12-01 07:11 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2010-11-24 07:57 . 2010-12-01 07:06 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2010-11-24 07:57 . 2010-11-27 12:54 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2010-11-24 07:42 . 2010-11-24 07:42 -------- d-sh--w- c:\windows\ftpcache
2010-11-24 07:25 . 2010-11-24 07:25 -------- d-----w- c:\program files (x86)\SQUARE ENIX - Eidos Interactive
2010-11-24 07:20 . 2010-11-24 07:20 -------- d-----w- c:\program files (x86)\GamePark
2010-11-23 21:27 . 2010-11-24 07:44 -------- d-----w- c:\program files (x86)\Activision
2010-11-23 17:43 . 1999-12-17 09:13 86016 ----a-w- c:\windows\unvise32.exe
2010-11-23 17:29 . 2010-11-23 17:29 -------- d-----w- c:\program files (x86)\IPCam
2010-11-23 14:24 . 2010-12-11 17:41 -------- d-----w- c:\windows\WindowsMobile
2010-11-23 14:17 . 2010-11-23 14:17 -------- d-----w- c:\programdata\Atheros
2010-11-23 13:13 . 2010-11-23 13:13 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2010-11-23 13:13 . 2010-11-25 08:24 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2010-11-23 12:54 . 2010-11-23 12:54 -------- d-----w- c:\program files (x86)\2K Games
2010-11-23 07:00 . 2010-11-23 07:00 -------- d-----w- c:\program files (x86)\SoftwareForMe Inc
2010-11-22 21:19 . 2010-11-22 21:19 -------- d-----w- c:\program files\SoftwareForMe Inc
2010-11-22 20:05 . 2010-11-22 20:05 -------- d-----w- c:\program files (x86)\Razer
2010-11-22 18:55 . 2010-11-22 18:55 -------- d-----w- C:\2cfebc502ba18a0f3666c1146b
2010-11-22 18:55 . 2010-11-22 18:55 -------- d-----w- c:\program files (x86)\MSXML 4.0
2010-11-22 18:54 . 2010-11-22 18:54 -------- d-----w- c:\windows\SysWow64\Wat
2010-11-22 18:54 . 2010-11-22 18:54 -------- d-----w- c:\windows\system32\Wat
2010-11-22 18:51 . 2010-11-22 18:51 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-11-22 18:51 . 2010-11-22 18:51 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-11-22 18:48 . 2010-11-22 18:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-11-22 18:48 . 2010-11-22 18:48 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2010-11-22 18:46 . 2010-11-23 02:02 -------- d-----w- c:\programdata\Microsoft Help
2010-11-22 18:45 . 2010-11-22 18:45 -------- d-----r- C:\MSOCache
2010-11-22 17:39 . 2010-05-11 11:00 20968 ----a-w- c:\windows\system32\drivers\cpuz133_x64.sys
2010-11-22 17:39 . 2010-11-26 07:12 -------- d-----w- c:\program files\CPUID
2010-11-22 16:53 . 2010-11-22 16:53 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-11-22 16:53 . 2010-11-22 16:53 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2010-11-22 16:53 . 2010-11-22 16:53 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-11-22 16:35 . 2010-11-22 16:35 -------- d-----w- c:\program files (x86)\VideoLAN
2010-11-22 16:05 . 2009-10-10 03:17 14336 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-11-22 16:04 . 2009-11-25 11:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2010-11-22 16:04 . 2009-11-25 11:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2010-11-22 16:04 . 2009-11-25 11:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2010-11-22 16:04 . 2009-11-25 11:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2010-11-22 16:04 . 2009-11-25 11:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2010-11-22 16:04 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2010-11-22 16:04 . 2009-11-25 11:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-11-22 16:04 . 2009-11-25 11:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2010-11-22 16:04 . 2009-11-25 11:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2010-11-22 16:04 . 2009-11-25 11:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2010-11-22 16:03 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2010-11-22 16:00 . 2010-12-13 08:08 -------- d-----w- c:\program files (x86)\Microsoft Antimalware
2010-11-22 15:57 . 2010-04-07 07:37 861184 ----a-w- c:\windows\system32\oleaut32.dll
2010-11-22 15:54 . 2010-09-01 02:58 3123712 ----a-w- c:\windows\system32\win32k.sys
2010-11-22 15:23 . 2010-11-22 15:23 -------- d-----w- c:\programdata\Sony
2010-11-22 15:23 . 2010-11-22 15:23 -------- d-----w- c:\program files\Sony
2010-11-22 15:23 . 2010-11-22 15:23 -------- d-----w- c:\program files (x86)\Sony
2010-11-22 15:23 . 2010-12-01 09:29 -------- d-----w- c:\program files\CCleaner
2010-11-22 15:18 . 2010-11-22 15:18 -------- d-----w- c:\program files (x86)\Lavalys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 18:46 . 2010-11-12 18:46 4280320 ----a-w- c:\windows\SysWow64\GPhotos.scr
.

((((((((((((((((((((((((((((( SnapShot@2010-12-13_08.16.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-24 12:07 . 2010-12-13 10:47 5302 c:\windows\system32\wdi\ERCQueuedResolutions.dat
- 2010-11-24 12:07 . 2010-12-11 23:11 5302 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2010-11-25 10:50 . 2010-12-13 09:48 293258 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Martinor\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Martinor\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Martinor\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2010-11-22 3265944]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2010-12-12 395640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-03-08 260608]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-21 98304]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-05-26 960080]

c:\users\Martinor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Martinor\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AVerQuick.lnk - c:\program files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-12-2 651264]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys [2010-05-20 55336]
R3 atillk64;atillk64;c:\program files (x86)\AMD GPU Clock Tool\atillk64.sys [x]
R3 AVerFx2hbtv64;AVerMedia USB SW Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv64.sys [2009-12-08 512512]
R3 flash;flash;c:\users\Martinor\Downloads\star\BIOS_Acer_1.19_A_A\BIOS_Acer_1.19_Windows\Winflash32\flash.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [2010-01-07 448512]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [2010-11-25 21200]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-11-22 1255736]
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\System32\drivers\sfdrv01a.sys [2009-02-03 77432]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-22 834544]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-04-21 202752]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2010-05-26 47776]
S2 AVerRemote;AVerRemote;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2009-10-30 348160]
S2 AVerScheduleService;AVerScheduleService;c:\program files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2009-12-07 397312]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x64.sys [2010-05-11 20968]
S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x64.sys [2010-07-09 21480]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-05-26 325200]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2010-01-20 819232]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2010-11-13 137792]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 PhoneMyPC_Helper;PhoneMyPC_Helper;c:\program files (x86)\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC_Helper.exe [2010-08-22 30208]
S2 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-04-21 6406144]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-04-21 188928]
S3 AmdTools64;AMD Special Tools Driver;c:\windows\system32\DRIVERS\AmdTools64.sys [2008-04-28 47160]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-12-02 40448]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2010-05-20 38248]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2010-05-20 294760]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2010-05-20 32296]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2010-05-20 202792]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2010-05-20 52584]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2010-05-20 156392]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2010-05-25 264040]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2010-04-21 10322848]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2009-12-22 74280]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]

.
Obsah adresáře 'Naplánované úlohy'

2010-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 15:21]

2010-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 15:21]
.

--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 97792 ----a-w- c:\users\Martinor\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 97792 ----a-w- c:\users\Martinor\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 97792 ----a-w- c:\users\Martinor\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-11-03 14:41 82136 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF5902.cfxxe" [X]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-22 323584]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-01-20 9996320]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-01-20 877600]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2010-05-26 585376]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2010-05-26 354464]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2010-03-09 345648]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2010-01-20 496160]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-21 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-21 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-21 413720]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 660360]
.
------- Doplňkový sken -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files (x86)\Internet Download Manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Martinor\AppData\Roaming\Mozilla\Firefox\Profiles\sz4lh5z9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/ig
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Fasterfox Extra: {ABD782DD-6EA5-4008-A03D-3FF46E886D38} - %profile%\extensions\{ABD782DD-6EA5-4008-A03D-3FF46E886D38}
FF - Ext: IDM CC: mozilla_cc@internetdownloadmanager.com - c:\users\Martinor\AppData\Roaming\IDM\idmmzcc3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

Toolbar-Locked - (no file)


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Launch Manager\LMworker.exe
.
**************************************************************************
.
Celkový čas: 2010-12-13 16:46:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-12-13 15:46
ComboFix2.txt 2010-12-13 08:17

Před spuštěním: Volných bajtů: 487 975 198 720
Po spuštění: Volných bajtů: 487 758 340 096

- - End Of File - - C34DB3E7428DD0BF43A10EF110569DE9
Lenovo IdeaPad S540-15IWL- verze 81SW000VCK

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu mého Aceru +

Příspěvekod jaro3 » 13 pro 2010 19:25

Stáhni si program OTM (by OldTimer)
a ulož si ho na disk C a spusť ho.
- Do levého sloupce (Paste Instructions for Items to be Moved) zkopíruj tyto cesty:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE

Kód: Vybrat vše

:Processes
explorer.exe

:Services

:Reg

:Files
C:\Windows\SysWow64\ezsidmv.dat
C:\Windows\¤ô+
C:\Windows\MOD01SET74CS0N0002.XML

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

- Po zkopírování klikni na tlačítko MoveIt! a vlož sem následně celý obsah z pravého sloupce, jinak uložený ve složce C:\_OTMoveIt\MovedFiles\, který bude informovat o výsledcích
- Je možné, že pokud nebudou moci být soubory odstraněny, budeš dotázán na restart počítače, v tom případě restart potvrď.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Martinor
Level 3
Level 3
Příspěvky: 437
Registrován: listopad 06
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu mého Aceru +

Příspěvekod Martinor » 13 pro 2010 19:56

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named :Services was found!
No active process named :Reg was found!
No active process named :Files was found!
No active process named C:\Windows\SysWow64\ezsidmv.dat was found!
No active process named C:\Windows\¤ô+ was found!
No active process named C:\Windows\MOD01SET74CS0N0002.XML was found!
No active process named :Commands was found!
No active process named [purity] was found!
No active process named [emptytemp] was found!
No active process named [start explorer] was found!
No active process named [Reboot] was found!

OTM by OldTimer - Version 3.1.17.2 log created on 12132010_195336
Lenovo IdeaPad S540-15IWL- verze 81SW000VCK

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu mého Aceru +

Příspěvekod jaro3 » 13 pro 2010 20:50

Zkus to ještě jednou , je třeba zkopírovat celý text.Je tam vpravo posuvník.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 48 hostů