[list=]RogueKiller V8.6.7 _x64_ [Aug 28 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora :
http://www.adlice.com/forum/Webové stránky :
http://www.adlice.com/softwares/roguekiller/ :
http://tigzyrk.blogspot.com/Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : djzdenek [Práva správce]
Mód : Odebrat -- Datum : 08/31/2013 19:08:59
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[EXT RUN][SUSP PATH] HKCU\djzdenek_ON_D:\[...]\Run : Google Update ("C:\Users\djzdenek\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]) -> VYMAZÁNO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
-> D:\windows\system32\config\SYSTEM | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\windows\system32\config\SOFTWARE | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\windows\system32\config\SECURITY | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\windows\system32\config\SAM | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\windows\system32\config\DEFAULT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\Users\Default\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> D:\Users\Default User\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> D:\Users\djzdenek\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\Documents and Settings\Default\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> D:\Documents and Settings\Default User\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> D:\Documents and Settings\djzdenek\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> D:\Documents and Settings\UpdatusUser\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: WDC WD50 00AAKS-22V1A0 SATA Disk Device +++++
--- User ---
[MBR] 22f38d2e0200135a5a9d506bbeb45369
[BSP] e58331b03eff12a6bbb5caafa9544f42 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: WDC WD50 00AAKS-22V1A0 SATA Disk Device +++++
--- User ---
[MBR] 10a575d1dd0d767075a5d757e3bf788e
[BSP] de1174bee4c800f9c6e4217f449dd771 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953765 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive2: WDC WD50 00AAKS-22V1A0 SATA Disk Device +++++
Error reading User MBR!
User = LL1 ... OK!
Error reading LL2 MBR!
+++++ PhysicalDrive3: WDC WD50 00AAKS-22V1A0 SATA Disk Device +++++
Error reading User MBR!
User = LL1 ... OK!
Error reading LL2 MBR!
+++++ PhysicalDrive4: WDC WD50 00AAKS-22V1A0 SATA Disk Device +++++
Error reading User MBR!
User = LL1 ... OK!
Error reading LL2 MBR!
Dokončeno : << RKreport[0]_D_08312013_190859.txt >>
RKreport[0]_S_08312013_111133.txt;RKreport[0]_S_08312013_190843.txt
[/list]
[list=]ComboFix 13-08-30.02 - djzdenek 31.08.2013 19:12:10.1.6 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8092.6049 [GMT 2:00]
Spuštěný z: c:\users\djzdenek\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\djzdenek\AppData\Roaming\Microsoft\Windows\Templates\1028.msi
c:\users\djzdenek\AppData\Roaming\Microsoft\Windows\Templates\1031.msi
c:\users\djzdenek\AppData\Roaming\Microsoft\Windows\Templates\1033.msi
c:\users\djzdenek\AppData\Roaming\Microsoft\Windows\Templates\1036.msi
c:\users\djzdenek\AppData\Roaming\Microsoft\Windows\Templates\1041.msi
c:\users\djzdenek\AppData\Roaming\Microsoft\Windows\Templates\2052.msi
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-28 do 2013-08-31 )))))))))))))))))))))))))))))))
.
.
2013-08-31 17:16 . 2013-08-31 17:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-31 09:19 . 2013-08-31 17:15 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7B3A1654-5DD4-4BCE-A010-E787428F668A}\offreg.dll
2013-08-31 09:12 . 2013-08-31 09:12 -------- d-----w- c:\windows\ERUNT
2013-08-30 19:27 . 2013-08-31 09:03 -------- d-----w- C:\AdwCleaner
2013-08-30 19:20 . 2013-08-30 19:20 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-30 19:20 . 2013-08-30 19:20 -------- d-----w- c:\programdata\Malwarebytes
2013-08-30 19:20 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-30 08:02 . 2012-09-19 09:51 34656 ----a-w- c:\windows\system32\TURegOpt.exe
2013-08-30 08:02 . 2012-09-19 09:51 25952 ----a-w- c:\windows\system32\authuitu.dll
2013-08-30 08:02 . 2012-09-19 09:51 21344 ----a-w- c:\windows\SysWow64\authuitu.dll
2013-08-30 08:02 . 2013-08-30 08:01 45856 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2013-08-30 08:01 . 2013-08-30 08:04 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2013
2013-08-30 08:01 . 2013-08-30 08:01 -------- d-----w- c:\programdata\TuneUp Software
2013-08-30 08:00 . 2013-08-30 22:14 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-08-30 08:00 . 2013-08-30 08:00 -------- d--h--w- c:\programdata\Common Files
2013-08-30 06:46 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7B3A1654-5DD4-4BCE-A010-E787428F668A}\mpengine.dll
2013-08-29 21:12 . 2013-08-29 21:12 -------- d-----w- c:\program files (x86)\Lavalys
2013-08-29 21:03 . 2013-08-29 21:03 -------- d-----w- c:\program files (x86)\CrystalDiskInfo
2013-08-29 05:57 . 2013-08-29 05:57 -------- d-----w- C:\Hry
2013-08-28 10:48 . 2013-08-28 10:52 -------- d-----w- c:\program files (x86)\Landwirtschafts Simulator 2011
2013-08-27 19:08 . 2013-08-27 19:10 -------- d-----w- c:\program files (x86)\AMD
2013-08-25 19:05 . 2013-08-25 19:06 -------- d-----r- c:\program files (x86)\Skype
2013-08-25 19:05 . 2013-08-25 19:05 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-08-25 19:05 . 2013-08-25 19:06 -------- d-----w- c:\programdata\Skype
2013-08-24 08:41 . 2013-08-24 08:41 -------- d-----w- c:\program files (x86)\7-Zip
2013-08-24 08:35 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-08-24 08:35 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-24 08:34 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-08-24 08:34 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-08-23 19:31 . 2013-04-11 12:10 2498216 ----a-w- c:\windows\SysWow64\BootMan.exe
2013-08-23 19:31 . 2013-03-28 17:02 3376640 ----a-w- c:\windows\system32\BootMan.exe
2013-08-23 19:31 . 2013-03-07 07:49 9160 ----a-w- c:\windows\SysWow64\EuGdiDrv.sys
2013-08-23 19:31 . 2013-03-07 07:49 87112 ----a-w- c:\windows\SysWow64\setupempdrv03.exe
2013-08-23 19:31 . 2013-03-07 07:49 13896 ----a-w- c:\windows\SysWow64\epmntdrv.sys
2013-08-23 19:31 . 2013-03-07 07:49 9800 ----a-w- c:\windows\system32\EuGdiDrv.sys
2013-08-23 19:31 . 2013-03-07 07:49 17480 ----a-w- c:\windows\system32\epmntdrv.sys
2013-08-23 19:31 . 2013-03-07 07:49 100936 ----a-w- c:\windows\system32\setupempdrvx64.exe
2013-08-23 19:31 . 2013-03-07 07:49 16256 ----a-w- c:\windows\system32\EuEpmGdi.dll
2013-08-23 19:31 . 2013-03-07 07:49 19840 ----a-w- c:\windows\SysWow64\EuEpmGdi.dll
2013-08-23 19:31 . 2013-08-23 19:31 -------- d-----w- c:\program files (x86)\EaseUS
2013-08-23 19:00 . 2013-08-23 19:00 -------- d-----w- c:\program files\7-Zip
2013-08-23 10:04 . 2013-08-23 10:04 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-08-23 08:34 . 2013-07-09 04:52 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-08-23 08:33 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-08-23 08:33 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-08-23 07:47 . 2013-08-23 07:47 -------- d-----w- c:\program files (x86)\PowerISO
2013-08-23 07:47 . 2012-12-09 09:51 126944 ----a-w- c:\windows\system32\drivers\scdemu.sys
2013-08-22 21:21 . 2013-08-22 21:21 -------- d-----w- c:\windows\system32\SPReview
2013-08-22 21:21 . 2013-08-22 21:21 -------- d-----w- c:\windows\system32\EventProviders
2013-08-22 14:20 . 2010-11-20 13:27 444416 ----a-w- c:\windows\system32\winhttp.dll
2013-08-22 14:19 . 2010-11-20 13:27 37376 ----a-w- c:\windows\system32\shimgvw.dll
2013-08-22 14:18 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2013-08-22 14:18 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll
2013-08-22 14:18 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll
2013-08-22 11:01 . 2013-08-22 11:01 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-08-22 10:56 . 2013-08-22 10:56 -------- d-----w- C:\NvidiaLogging
2013-08-22 10:55 . 2013-05-14 19:28 39712 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-08-22 10:55 . 2013-05-14 19:27 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-08-22 10:55 . 2013-05-14 19:27 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-08-22 08:16 . 2013-08-22 08:16 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-08-21 21:32 . 2013-08-21 21:32 -------- d-----w- c:\windows\SysWow64\Wat
2013-08-21 21:32 . 2013-08-21 21:32 -------- d-----w- c:\windows\system32\Wat
2013-08-21 19:30 . 2013-08-21 19:30 -------- d-----w- C:\Games
2013-08-21 19:20 . 2013-08-21 19:20 -------- d-----w- c:\program files (x86)\TeamViewer
2013-08-21 17:53 . 2012-07-26 07:40 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
2013-08-21 17:53 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-08-21 17:53 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-08-21 17:53 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-08-21 17:42 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-08-21 17:40 . 2013-08-21 17:41 -------- d-----w- c:\windows\system32\MRT
2013-08-21 17:26 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2013-08-21 17:26 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2013-08-21 17:26 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-08-21 17:26 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-08-21 17:26 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2013-08-21 17:26 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2013-08-21 17:25 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-08-21 17:25 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-08-21 17:25 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-08-21 17:25 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-08-21 17:25 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-08-21 17:25 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-08-21 17:25 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-08-21 17:16 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-08-21 17:16 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-08-21 17:16 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-08-21 17:16 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-08-21 17:16 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-08-21 17:15 . 2013-08-30 19:07 -------- d-----w- c:\users\UpdatusUser
2013-08-21 17:15 . 2013-06-20 04:17 3253909 ----a-w- c:\windows\system32\nvcoproc.bin
2013-08-21 17:07 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-08-21 17:06 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2013-08-21 17:06 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2013-08-21 17:06 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2013-08-21 17:06 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe
2013-08-21 17:06 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
2013-08-21 17:06 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll
2013-08-21 17:06 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2013-08-21 17:06 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2013-08-21 17:06 . 2010-11-20 13:27 33792 ----a-w- c:\windows\system32\profprov.dll
2013-08-21 17:06 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe
2013-08-21 17:06 . 2010-11-20 13:25 974336 ----a-w- c:\windows\system32\WFS.exe
2013-08-21 17:01 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2013-08-21 17:01 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2013-08-21 17:00 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2013-08-21 17:00 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2013-08-21 17:00 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2013-08-21 17:00 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2013-08-21 17:00 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-08-21 16:56 . 2013-08-21 16:56 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2013-08-21 16:45 . 2013-08-21 16:45 1998168 ----a-w- c:\windows\SysWow64\d3dx9_43.dll
2013-08-21 16:45 . 2013-08-21 16:45 -------- d-----w- c:\programdata\Logs
2013-08-21 16:28 . 2013-08-21 16:28 -------- d-----w- C:\direct
2013-08-21 15:27 . 2013-08-21 15:27 -------- d-----w- c:\program files (x86)\dreamboxEDIT
2013-08-21 15:16 . 2010-12-02 17:12 1359976 ----a-w- c:\windows\system32\nvgenco64hda.dll
2013-08-21 15:16 . 2013-08-31 17:02 -------- d-----w- c:\programdata\NVIDIA
2013-08-21 15:15 . 2013-08-22 11:01 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2013-08-21 15:15 . 2013-08-22 10:56 -------- d-----w- c:\programdata\NVIDIA Corporation
2013-08-21 15:15 . 2011-01-16 23:53 1614440 ----a-w- c:\windows\system32\nvdispco642090.dll
2013-08-21 15:15 . 2011-01-16 23:53 1359976 ----a-w- c:\windows\system32\nvgenco642040.dll
2013-08-21 15:15 . 2011-01-16 23:53 67176 ----a-w- c:\windows\system32\OpenCL.dll
2013-08-21 15:15 . 2011-01-16 23:53 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-08-21 15:14 . 2013-06-21 12:06 2936208 ----a-w- c:\windows\system32\nvapi64.dll
2013-08-21 15:14 . 2013-06-21 12:06 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-08-21 15:14 . 2011-01-16 23:53 11240 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-23 21:27 . 2013-08-23 21:27 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-08-23 21:27 . 2013-08-23 21:27 204800 ----a-w- c:\windows\SysWow64\webcheck.dll
2013-08-23 06:55 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2013-08-23 06:55 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2013-06-21 12:06 . 2013-02-25 22:32 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-06-21 12:06 . 2013-02-25 22:32 1059560 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-06-21 12:06 . 2013-02-25 22:32 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-06-21 10:23 . 2011-01-16 15:13 6496544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 10:23 . 2011-01-16 15:13 3514656 ----a-w- c:\windows\system32\nvsvc64.dll
2013-06-21 10:23 . 2011-01-16 15:13 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 10:23 . 2011-01-16 15:13 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 10:23 . 2011-01-16 15:13 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-06-21 10:23 . 2011-01-16 15:13 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-21 03:16 . 2013-06-21 03:16 566048 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"LocalAccountTokenFilterPolicy"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\NVIDIA~1\NVSTRE~1\rxinput.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
R2 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 vToolbarUpdater15.4.0;vToolbarUpdater15.4.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [x]
R3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys;SysWow64\drivers\ASUSFILTER.sys [x]
R3 atillk64;atillk64;c:\program files (x86)\AMD\System Monitor\atillk64.sys;c:\program files (x86)\AMD\System Monitor\atillk64.sys [x]
R3 cpuz135;cpuz135;c:\users\djzdenek\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\djzdenek\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys;c:\windows\SYSNATIVE\epmntdrv.sys [x]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys;c:\windows\SYSNATIVE\EuGdiDrv.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 ndisrd;WinpkFilter LightWeight Filter;c:\windows\system32\DRIVERS\ndisrd.sys;c:\windows\SYSNATIVE\DRIVERS\ndisrd.sys [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys;c:\windows\SYSNATIVE\DRIVERS\VDiskBus64.sys [x]
S2 AODDriver4.2.0;AODDriver4.2.0;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [x]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [x]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUSTek Computer Inc\Disk Unlocker\ASPFSVS64.exe;c:\program files (x86)\ASUSTek Computer Inc\Disk Unlocker\ASPFSVS64.exe [x]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [x]
S2 AsusFanControlService;AsusFanControlService;c:\program files (x86)\ASUS\AsusFanControlService\1.01.10\AsusFanControlService.exe;c:\program files (x86)\ASUS\AsusFanControlService\1.01.10\AsusFanControlService.exe [x]
S2 DTSAudioSvc;DTSAudioSvc;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x]
S3 AiChargerPlus;AiChargerPlus;SysWow64\drivers\AiChargerPlus.sys;SysWow64\drivers\AiChargerPlus.sys [x]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUSTek Computer Inc\Disk Unlocker\ASFLTDrv64.sys;c:\program files (x86)\ASUSTek Computer Inc\Disk Unlocker\ASFLTDrv64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ASFLTDRV.SYS
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-30 19:58 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-21 14:53]
.
2013-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-21 14:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-08-07 6827664]
"RtHDVBg_DTS"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-08-06 1215632]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~1\NVIDIA~1\NVSTRE~1\rxinput.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.132.12.33 10.132.12.1
FF - ProfilePath - c:\users\djzdenek\AppData\Roaming\Mozilla\Firefox\Profiles\mows4i12.default\
FF - ExtSQL: 2013-08-25 21:06; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Dll-Files Fixer_is1 - c:\program files (x86)\Dll-Files.com Fixer\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-08-31 19:18:23
ComboFix-quarantined-files.txt 2013-08-31 17:18
.
Před spuštěním: Volných bajtů: 405 328 072 704
Po spuštění: Volných bajtů: 405 211 115 520
.
- - End Of File - - 649C80C391B11B6D319E335635E338D3
5FB38429D5D77768867C76DCBDB35194
[/list]