Log HJT Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Log HJT

Příspěvekod Clorky » 14 dub 2012 09:52

Zdravím, delší dobu jsem nečistil PC od havěti. Nemyslím si, že i po reinstallu (před 3-4 měsícema) dosahuje stejného výkonu.
Předem Vám děkuji za pomoc.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:51:35, on 14.4.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
E:\Optimalizace\Advanced SystemCare 5\ASCTray.exe
C:\Users\Clorky\AppData\Local\Facebook\Messenger\2.0.4478.0\FacebookMessenger.exe
C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
C:\PROGRAM FILES (X86)\HAMACHI\HAMACHI.EXE
C:\PROGRAM FILES (X86)\SKYPE\PHONE\SKYPE.EXE
E:\Programy\Mozilla Firefox 4.0\firefox.exe
E:\Programy\Mozilla Firefox 4.0\plugin-container.exe
E:\Programy\Mozilla Firefox 4.0\plugin-container.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Users\Clorky\Desktop\Modpack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Advanced SystemCare 5] "E:\Optimalizace\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Facebook Messenger.lnk = Clorky\AppData\Local\Facebook\Messenger\2.0.4478.0\FacebookMessenger.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - E:\Optimalizace\Advanced SystemCare 5\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASO3DiskOptimizer - Systweak Inc., (www.systweak.com) - C:\Program Files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - C:\Users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\mysqld-nt.exe
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RadeonPro Support Service - Mr. John aka japamd - C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: SafeBox - Bitdefender - C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (UPDATESRV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 7314 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod jaro3 » 14 dub 2012 10:20

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/s ... wflash.cab


Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Clorky » 14 dub 2012 12:12

ATF nevidí Firefox. Je v šedém.
Main jsem udělal.

Malwarebytes:
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org

Database version: v2012.04.14.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Clorky :: I5PETR [administrator]

Protection: Enabled

14.4.2012 12:08:42
mbam-log-2012-04-14 (12-12-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 194547
Time elapsed: 3 minute(s), 16 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> No action taken.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> No action taken.

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Žbeky » 14 dub 2012 18:10

Znovu spusť MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Clorky » 14 dub 2012 18:16

MbAM vše v pořádku, ten log jsem neuložil, snad to nevadí.
Za chvíli dodám Combofix. Začínám s ním.

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Clorky » 14 dub 2012 19:07

Zrovna jsem přeinstalovával avast. Nešel mi nějak vypnout když jsem zapínal CF (po installu avasta se zeptal jestli restart, dal jsem později, zapl CF a až poté restartnul). Pokud to má vliv na log, udělám to znova. Tak se omlouvám že takhle zmatkuju.
Tady to je:

ComboFix 12-04-14.02 - Clorky 14.04.2012 18:51:10.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.4094.2642 [GMT 2:00]
Spuštěný z: c:\users\Clorky\Desktop\ComboFix.exe
AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setup.dll
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.dat
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.exe
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.ico
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\windows\My.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-14 do 2012-04-14 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 15:17 . 2012-02-29 18:34 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-13 11:17 . 2012-02-29 20:39 839112 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-31 10:50 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-03-31 10:50 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-03-30 19:42 . 2012-01-18 16:16 691896 ----a-w- c:\windows\system32\drivers\avc3.sys
2012-03-09 19:45 . 2012-03-09 19:45 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-07 23:40 . 2012-03-07 23:40 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-03-07 23:40 . 2012-03-07 23:40 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-03-07 23:40 . 2012-03-07 23:40 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-03-07 23:40 . 2012-03-07 23:40 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-03-07 23:40 . 2012-03-07 23:40 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-03-07 23:40 . 2012-03-07 23:40 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-03-07 23:40 . 2012-03-07 23:40 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-03-07 23:40 . 2012-03-07 23:40 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-03-07 23:40 . 2012-03-07 23:40 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-03-07 23:40 . 2012-03-07 23:40 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-03-07 23:40 . 2012-03-07 23:40 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-03-07 23:40 . 2012-03-07 23:40 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-03-07 23:40 . 2012-03-07 23:40 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-03-07 23:40 . 2012-03-07 23:40 448512 ----a-w- c:\windows\system32\html.iec
2012-03-07 23:40 . 2012-03-07 23:40 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-03-07 23:40 . 2012-03-07 23:40 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-03-07 23:40 . 2012-03-07 23:40 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-03-07 23:40 . 2012-03-07 23:40 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-07 23:40 . 2012-03-07 23:40 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-03-07 23:40 . 2012-03-07 23:40 222208 ----a-w- c:\windows\system32\msls31.dll
2012-03-07 23:40 . 2012-03-07 23:40 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-03-07 23:40 . 2012-03-07 23:40 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-03-07 23:40 . 2012-03-07 23:40 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-03-07 23:40 . 2012-03-07 23:40 160256 ----a-w- c:\windows\system32\wextract.exe
2012-03-07 23:40 . 2012-03-07 23:40 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-03-07 23:40 . 2012-03-07 23:40 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-03-07 23:40 . 2012-03-07 23:40 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-03-07 23:40 . 2012-03-07 23:40 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-03-07 23:40 . 2012-03-07 23:40 12288 ----a-w- c:\windows\system32\mshta.exe
2012-03-07 23:40 . 2012-03-07 23:40 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-03-07 23:40 . 2012-03-07 23:40 114176 ----a-w- c:\windows\system32\admparse.dll
2012-03-07 23:40 . 2012-03-07 23:40 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-03-07 23:40 . 2012-03-07 23:40 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-03-07 23:40 . 2012-03-07 23:40 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-03-03 16:15 . 2012-03-03 16:15 74703 ----a-w- c:\windows\SysWow64\mfc45.dll
2012-03-03 14:23 . 2012-03-03 14:23 27136 ------w- c:\windows\system32\bddel.exe
2012-03-01 18:25 . 2012-03-01 18:25 545064 ----a-w- c:\windows\system32\drivers\avckf.sys
2012-03-01 09:04 . 2012-03-01 09:04 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-29 20:04 . 2012-02-29 20:04 540176 ----a-w- c:\programdata\1330543295.bdinstall.bin
2012-02-29 19:30 . 2012-02-29 19:30 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-29 19:30 . 2012-02-29 19:30 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-29 19:29 . 2012-02-29 19:29 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-29 19:29 . 2012-02-29 19:29 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-29 19:29 . 2012-02-29 19:29 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-29 19:27 . 2012-02-29 19:27 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-29 19:27 . 2012-02-29 19:27 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-29 19:26 . 2012-02-29 19:26 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-02-29 19:26 . 2012-02-29 19:26 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-02-29 19:26 . 2012-02-29 19:26 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-02-29 19:26 . 2012-02-29 19:26 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-02-29 19:26 . 2012-02-29 19:26 459232 ----a-w- c:\windows\system32\drivers\cng.sys
2012-02-29 19:26 . 2012-02-29 19:26 395776 ----a-w- c:\windows\system32\webio.dll
2012-02-29 19:26 . 2012-02-29 19:26 340992 ----a-w- c:\windows\system32\schannel.dll
2012-02-29 19:26 . 2012-02-29 19:26 314880 ----a-w- c:\windows\SysWow64\webio.dll
2012-02-29 19:26 . 2012-02-29 19:26 31232 ----a-w- c:\windows\system32\lsass.exe
2012-02-29 19:26 . 2012-02-29 19:26 29184 ----a-w- c:\windows\system32\sspisrv.dll
2012-02-29 19:26 . 2012-02-29 19:26 28160 ----a-w- c:\windows\system32\secur32.dll
2012-02-29 19:26 . 2012-02-29 19:26 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-02-29 19:26 . 2012-02-29 19:26 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-02-29 19:26 . 2012-02-29 19:26 152432 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-02-29 19:26 . 2012-02-29 19:26 1447936 ----a-w- c:\windows\system32\lsasrv.dll
2012-02-29 19:26 . 2012-02-29 19:26 136192 ----a-w- c:\windows\system32\sspicli.dll
2012-02-29 19:26 . 2012-02-29 19:26 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-02-29 19:26 . 2012-02-29 19:26 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-02-29 19:26 . 2012-02-29 19:26 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-02-29 19:26 . 2012-02-29 19:26 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-02-29 19:25 . 2012-02-29 19:25 77312 ----a-w- c:\windows\system32\packager.dll
2012-02-29 19:25 . 2012-02-29 19:25 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-02-29 19:24 . 2012-02-29 19:24 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-02-29 19:24 . 2012-02-29 19:24 2048 ----a-w- c:\windows\system32\tzres.dll
2012-02-29 19:24 . 2012-02-29 19:24 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-02-29 19:23 . 2012-02-29 19:23 723456 ----a-w- c:\windows\system32\EncDec.dll
2012-02-29 19:23 . 2012-02-29 19:23 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-02-29 19:21 . 2012-02-29 19:21 288640 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-02-29 19:21 . 2012-02-29 19:21 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-02-29 19:12 . 2012-02-29 19:12 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-02-29 19:12 . 2012-02-29 19:12 75776 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 72704 ----a-w- c:\windows\SysWow64\Mpeg2Data.ax
2012-02-29 19:12 . 2012-02-29 19:12 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-02-29 19:12 . 2012-02-29 19:12 59904 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-02-29 19:12 . 2012-02-29 19:12 288256 ----a-w- c:\windows\system32\MSNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 204288 ----a-w- c:\windows\SysWow64\MSNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-02-29 19:12 . 2012-02-29 19:12 104960 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-02-29 19:12 . 2012-02-29 19:12 861696 ----a-w- c:\windows\system32\oleaut32.dll
2012-02-29 19:12 . 2012-02-29 19:12 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2012-02-29 19:12 . 2012-02-29 19:12 331776 ----a-w- c:\windows\system32\oleacc.dll
2012-02-29 19:12 . 2012-02-29 19:12 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2012-02-29 19:10 . 2012-02-29 19:10 212992 ----a-w- c:\windows\system32\odbctrac.dll
2012-02-29 19:10 . 2012-02-29 19:10 163840 ----a-w- c:\windows\system32\odbccp32.dll
2012-02-29 19:10 . 2012-02-29 19:10 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll
2012-02-29 19:10 . 2012-02-29 19:10 106496 ----a-w- c:\windows\system32\odbccu32.dll
2012-02-29 19:10 . 2012-02-29 19:10 106496 ----a-w- c:\windows\system32\odbccr32.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\via\viaudioi\vdeck\vdeck.exe" [2010-08-11 2472048]
"StartCCC"="c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe" [2012-02-14 636032]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2012-01-03 843712]
"Adobe Reader Speed Launcher"="c:\program files (x86)\adobe\reader 10.0\reader\reader_sl.exe" [2011-01-30 35736]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-02-23 4031368]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 10752]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x]
R1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 253088]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [x]
R3 bdsandbox;bdsandbox;c:\windows\system32\drivers\bdsandbox.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-04-07 19952]
R3 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-02-14 736104]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [x]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe [2011-11-02 263480]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-02-23 131288]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2010-09-26 724152]
S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2010-09-26 724152]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-11-17 3273552]
S2 RadeonPro Support Service;RadeonPro Support Service;c:\program files (x86)\RadeonPro\RadeonProSupport.exe [2011-02-10 12800]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ASWFW
*NewlyCreated* - ASWSNX
*NewlyCreated* - WS2IFSL
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de188baa-6374-11e1-9c6f-e0cb4e05e67f}]
\shell\AutoRun\command - G:\BSAutoRun.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-04-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 15:17]
.
2012-04-14 c:\windows\Tasks\ASO-AutoCheckUpdate7Days.job
- c:\program files (x86)\Advanced System Optimizer 3\CheckUpdate.exe [2012-03-03 18:24]
.
2012-04-01 c:\windows\Tasks\ASO-OneClickCare.job
- c:\program files (x86)\Advanced System Optimizer 3\ASO3.exe [2012-03-03 18:23]
.
2012-03-03 c:\windows\Tasks\ASOService.job
- c:\program files (x86)\Advanced System Optimizer 3\ASO3.exe [2012-03-03 18:23]
.
2012-04-14 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001Core.job
- c:\users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-12 11:25]
.
2012-04-14 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001UA.job
- c:\users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-12 11:25]
.
2012-04-14 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2012-04-14 21:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-02-23 15:23 135408 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2011-11-17 3994960]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe" [2011-03-15 499608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
FF - ProfilePath - c:\users\Clorky\AppData\Roaming\Mozilla\Firefox\Profiles\nzoqllew.default\
FF - prefs.js: browser.startup.homepage - http://www.google.cz
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: extentions.y2layers.installId - 567c00ab-1858-4585-8dda-e3e6e7fc816e
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,TopRelatedTopics,BestVideoDownloader,
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
.
.
------- Asociace souborů -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{152C96EB-288E-4EDC-B7C6-D21F8250ADF3} - c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
ShellIconOverlayIdentifiers-{342DAA0B-D796-460D-8566-901E08A1CCAD} - c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
ShellIconOverlayIdentifiers-{57595DAE-1AE1-4D97-A49E-67CBB53B52DF} - c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
ShellIconOverlayIdentifiers-{33816773-98AE-4723-ADE0-EBE54C8B5A67} - c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
HKLM-Run-BDAgent - c:\program files\Bitdefender\Bitdefender 2012\bdagent.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mysql]
"ImagePath"="c:\users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\mysqld-nt --defaults-file=c:\users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\my.cnf mysql"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1365180198-3819917712-2369891476-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ca,88,93,ea,23,f9,36,80,af,e7,8c,9b,3f,44,58,fc,77,04,3d,15,f2,5c,9a,
b4,56,b9,5d,a8,c4,76,a3,75,e8,85,8e,a6,cd,a8,1e,2e,4b,e1,69,6e,14,98,2c,99,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-1365180198-3819917712-2369891476-1001\Software\SecuROM\License information*]
"datasecu"=hex:05,e1,cf,03,79,da,b9,b5,7a,58,86,bd,7b,91,11,58,39,96,0f,04,1f,
60,d7,cf,05,7a,e7,4e,ea,a8,42,70,9f,9a,f8,a7,a1,ad,d0,ca,ea,a2,4c,3d,85,e5,\
"rkeysecu"=hex:9d,18,c2,66,c4,3c,cc,22,3e,ff,2e,38,89,b9,73,55
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG15.00.00.01PROFESSIONAL"="CFE1CA2B0F975DAD4D9EB25DEA92878C93B8ECAB521C7EEA39E3EC839017D1EE4911C78A1B75336D1264B7FB6F9FC66F968BBADE0524058D78513DFD473F32958A115042A82F5C855CEE78493D596C54EAE309DE6B3D4E08CE9D0AB62A379E1F87A8B500CE9B70CA506F01C66C949CF307803AA240D7A599A2B3B0B7B4AEAB7038106C066A476E64950C7D0C5AD85C5B63955537031B3A52DC75AF222687D13E97F40EA79BF0364D5A5FC0C12863976B7E4984B9F2DF9F98EE352C2A02D8ED94A677564FC58B8F574DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D1407BA7FD869164D67949DB7CE019D40AA5C838FACAD88F720A3481AB483170CBD662E5E8C032449C738B75445831C8F294696B6C6A0AA54923A9C32A04E0C2B75CCF2B9AD6F35D1C873AB5A038B4258268F99A9AF8A4150AFB800BD4D824191C6920FBAE1153D071AB32DE81063C71B771C176494051BA079B8CBD29B1DE0DB7B8046AF5F74E18FE8920EA915A972A54FF51087B470BA5DC5D54C28015E4B8CAF61D40A6F4C8176B7AC96E4543F39ADB1A9F657E46E5681C12E439D86CA930851076860F1A1AB2AD724818B20CBCBC8FACDB5BA0DE6D8EF6A6565B249A90198244521EBD7BFA5FB751FFCAF5E380B7157F5A83EA905DF6B13A55C0B7A888FEAC176970BA7B2E7220C46AD870CB30D0AC83E9C11CB383F9CE297C3F1E035EE1294F4D4BE7CCA1E386B47286FB7301BD324C4D80817B2FC1054EC2ED2D24602015CA3D5AE039EA93DB9D4FAE50563B1F6952C151AC2EC543635579E3FC012E013ADE50EA300069F91EE24A10DAB4804FE191B7B641D22B2E22A91116BAA36570470A4E38A471FC67D586E11ACF49B755A02BC2D2605CFBA4FA8546FB0A491E3F6DFCB2FF6C44A1DAA16F130AE42E0A15DF3BE3EC2EEBAC2977BE09D8B594ABAF08A4E401EF5ADD2269E6FD923065DD5BFE9D43743E268563C42F96E9D06C5C359569D575A6C32CB6438ADDBBCC79B929BB0B593527E2633216EE62B2CFB321A00FAB52CA85004213B81767B51A2690EF06C9AC2C07001CC10C875921E1FFE8C950290E6AB5A9420E46A16EE5C45DAB02410C22981FE4DC7B3E9725402EA609FAF4DAFA7A8591BC67FB75EDFFDF4C21AFA67F29FAD80A1011EC1B41609EACE8AC690187E8B300D4D8D0327EFF686BD1A228FEEF080E0DA06C19311EE864186B839D1D2F25F542B987538462F30E6A9B6A7F982DE59A29518F875E36EF42386CAC76E6B7ED6CFF4C702989D263293272A016C7C1B3E58362FFE510E95EFD893131816730EC8C2AE2AE0390B50AEA29EE00401AE4FD4AB6475F36772D6B941B798B44CFE06AFDCE244A602779C77B8397C6B27F0186A570A4A5DC9"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
c:\program files\AVAST Software\Avast\setup\avast.setup
.
**************************************************************************
.
Celkový čas: 2012-04-14 19:06:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-14 17:06
.
Před spuštěním: 190 715 170 816 bytes free
Po spuštění: 190 352 297 984 bytes free
.
- - End Of File - - DB9C9F9A48C88A869B0A57DD2BB8FF9A

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod jaro3 » 15 dub 2012 09:22

Jsou tam stále soubory po BitDefenderu , zkus odinstalovat tímto:
BitDefender Uninstall:
http://www.bitdefender.com/uninstall

Pak znovu sken Combofixem.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Clorky » 15 dub 2012 10:28

Fajn, dal jsem ještě full scan přes avast, ale musel jsem to zastavit, pač by to trvalo 20h. Každopádně našel dva trojany s nízkým rizikem, dal jsem je odstranit. Byly to .exe soubory.
CF dodám do hodiny.

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Clorky » 15 dub 2012 10:57

Tady to je.

ComboFix 12-04-14.02 - Clorky 15.04.2012 10:47:23.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.4094.2591 [GMT 2:00]
Spuštěný z: c:\users\Clorky\Desktop\Download\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-15 do 2012-04-15 )))))))))))))))))))))))))))))))
.
.
2012-04-15 08:50 . 2012-04-15 08:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-14 18:13 . 2012-04-14 18:13 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F2CC860-4B70-4C50-8576-AAB417E199B3}\offreg.dll
2012-04-14 16:41 . 2012-03-06 23:04 337240 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-04-14 16:41 . 2012-03-06 23:01 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-04-14 16:41 . 2012-03-06 23:04 141144 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-04-14 16:40 . 2012-03-06 23:03 258904 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-04-14 16:40 . 2012-03-06 23:02 53080 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-04-14 16:40 . 2012-03-06 23:02 28504 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-04-14 16:40 . 2012-03-06 23:01 59224 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-04-14 16:40 . 2012-03-06 23:04 819032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-04-14 16:40 . 2012-03-06 23:01 69976 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-04-14 16:40 . 2012-03-06 23:15 258520 ----a-w- c:\windows\system32\aswBoot.exe
2012-04-14 16:40 . 2012-02-23 14:54 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-04-14 16:40 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-04-14 16:40 . 2012-03-06 23:15 201352 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-04-14 16:40 . 2012-04-14 16:40 -------- d-----w- c:\programdata\AVAST Software
2012-04-14 16:40 . 2012-04-14 16:40 -------- d-----w- c:\program files\AVAST Software
2012-04-14 16:24 . 2012-04-14 16:24 1550 ----a-w- c:\programdata\1334420640.bdinstall.bin
2012-04-14 16:23 . 2012-04-14 16:23 1550 ----a-w- c:\programdata\1334420635.bdinstall.bin
2012-04-14 16:23 . 2012-04-14 16:23 125115 ----a-w- c:\programdata\1334420597.bdinstall.bin
2012-04-14 16:20 . 2012-04-14 16:20 -------- d-----w- c:\users\Clorky\AppData\Local\Adobe
2012-04-14 15:17 . 2012-04-14 15:17 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-14 13:38 . 2012-04-14 13:38 -------- d-----w- c:\programdata\BDLogging
2012-04-14 13:23 . 2012-04-14 13:23 -------- d-----w- c:\users\Clorky\AppData\Roaming\GlarySoft
2012-04-14 13:21 . 2012-04-14 13:21 -------- d-----w- c:\program files (x86)\Glary Utilities
2012-04-14 10:15 . 2012-04-14 10:27 -------- d-----w- c:\users\Clorky\AppData\Roaming\Bioshock
2012-04-14 09:54 . 2012-04-14 09:54 -------- d-----w- c:\users\Clorky\AppData\Roaming\Malwarebytes
2012-04-14 09:54 . 2012-04-14 09:54 -------- d-----w- c:\programdata\Malwarebytes
2012-04-14 09:54 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-14 09:54 . 2012-04-14 09:54 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-13 11:17 . 2012-04-13 11:17 -------- d-----w- c:\program files\Java
2012-04-13 11:09 . 2012-04-13 11:17 955848 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-04-13 11:05 . 2012-04-13 12:12 -------- d-----w- c:\users\Clorky\AppData\Roaming\.Nitrous
2012-04-13 08:53 . 2012-03-14 03:27 8669240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F2CC860-4B70-4C50-8576-AAB417E199B3}\mpengine.dll
2012-04-12 20:30 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 20:30 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-12 20:30 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-12 20:30 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-12 20:30 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-12 20:30 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-12 20:30 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-12 18:28 . 2012-04-12 18:28 -------- d-----w- c:\users\Clorky\AppData\Local\Irrational Games
2012-04-12 16:00 . 2012-04-14 18:50 -------- d-----w- c:\users\Clorky\AppData\Roaming\.minecraft
2012-04-12 11:25 . 2012-04-12 11:26 -------- d-----w- c:\users\Clorky\AppData\Local\Facebook
2012-04-09 17:38 . 2012-04-09 17:38 -------- d-----w- c:\program files (x86)\Convert AVI to MP4
2012-04-08 08:50 . 2012-04-08 08:50 -------- d-----w- c:\users\Clorky\AppData\Local\Rockstar Games
2012-04-07 22:02 . 2012-04-07 22:02 -------- d-----w- c:\program files (x86)\AviSynth 2.5
2012-04-07 18:15 . 2012-04-07 20:08 -------- d-----w- c:\users\Clorky\AppData\Roaming\TS3Client
2012-04-07 18:15 . 2012-04-07 18:15 -------- d-----w- c:\users\Clorky\AppData\Local\TeamSpeak 3 Client
2012-04-07 14:30 . 2012-04-07 14:31 -------- d-----w- c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2012-04-07 09:57 . 2012-04-07 09:57 -------- d-sh--w- c:\programdata\SecuROM
2012-04-07 09:57 . 2012-04-07 09:57 -------- d--h--r- c:\users\Clorky\AppData\Roaming\SecuROM
2012-04-07 09:46 . 2012-04-07 09:46 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-04-04 15:33 . 2004-04-18 21:42 733184 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iKernel.dll
2012-04-04 15:33 . 2004-04-18 21:40 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\ctor.dll
2012-04-04 15:33 . 2004-04-18 21:39 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iscript.dll
2012-04-04 15:33 . 2004-04-18 21:39 172032 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iuser.dll
2012-04-04 15:33 . 2004-04-18 21:39 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\DotNetInstaller.exe
2012-04-04 15:33 . 2012-04-04 15:33 180356 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iGdi.dll
2012-04-04 15:33 . 2012-04-04 15:33 303236 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\setup.dll
2012-03-31 21:29 . 2012-03-31 21:29 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2012-03-31 21:29 . 2012-03-31 21:29 -------- d-----w- c:\windows\SysWow64\AGEIA
2012-03-31 21:29 . 2012-03-31 21:29 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-03-31 15:46 . 2012-03-31 15:46 -------- d-----w- c:\program files (x86)\Nuclear Coffee
2012-03-31 11:19 . 2012-01-25 06:38 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-03-31 11:19 . 2012-01-25 06:38 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-31 10:33 . 2012-03-31 10:33 -------- d-----w- c:\users\Clorky\AppData\Local\Mumble
2012-03-31 09:51 . 2012-03-31 22:20 -------- d-----w- c:\users\Clorky\AppData\Roaming\Mumble
2012-03-31 09:50 . 2012-03-31 09:50 -------- d-----w- c:\program files (x86)\Mumble
2012-03-31 07:47 . 2004-01-11 22:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-03-31 07:47 . 2003-03-19 01:14 499712 ----a-w- c:\windows\system32\MSVCP71.DLL
2012-03-31 07:28 . 2012-03-31 07:28 -------- d-----w- c:\users\Clorky\AppData\Roaming\XRay Engine
2012-03-31 06:24 . 2012-03-31 06:24 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-03-29 13:43 . 2012-04-14 15:17 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-28 18:45 . 2012-03-28 18:45 -------- d-----w- c:\users\Clorky\AppData\Local\SKIDROW
2012-03-28 18:44 . 2012-03-28 18:44 -------- d-----w- c:\program files (x86)\Microsoft XNA
2012-03-27 13:32 . 2012-03-27 13:34 -------- d-----w- c:\users\Clorky\AppData\Local\SkyrimMTO
2012-03-26 19:43 . 2012-03-26 19:43 -------- d-----w- c:\program files\NVIDIA Corporation
2012-03-26 19:42 . 2012-03-26 19:42 61440 ----a-w- c:\windows\SysWow64\nvPhotoshopUtil.dll
2012-03-20 18:35 . 2012-03-20 18:35 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2012-03-20 18:35 . 2012-03-20 18:35 188548 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2012-03-20 18:35 . 2003-11-10 17:14 729088 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2012-03-20 18:35 . 2003-11-10 17:13 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2012-03-20 18:35 . 2003-11-10 17:12 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2012-03-20 18:35 . 2003-11-10 17:12 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2012-03-20 18:35 . 2003-11-10 17:11 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-03-17 10:24 . 2012-03-17 10:24 -------- d-----w- c:\users\Clorky\AppData\Roaming\DarksporeData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 15:17 . 2012-02-29 18:34 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-13 11:17 . 2012-02-29 20:39 839112 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-31 10:50 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-03-31 10:50 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-03-09 19:45 . 2012-03-09 19:45 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-07 23:40 . 2012-03-07 23:40 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-03-07 23:40 . 2012-03-07 23:40 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-03-07 23:40 . 2012-03-07 23:40 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-03-07 23:40 . 2012-03-07 23:40 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-03-07 23:40 . 2012-03-07 23:40 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-03-07 23:40 . 2012-03-07 23:40 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-03-07 23:40 . 2012-03-07 23:40 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-03-07 23:40 . 2012-03-07 23:40 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-03-07 23:40 . 2012-03-07 23:40 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-03-07 23:40 . 2012-03-07 23:40 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-03-07 23:40 . 2012-03-07 23:40 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-03-07 23:40 . 2012-03-07 23:40 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-03-07 23:40 . 2012-03-07 23:40 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-03-07 23:40 . 2012-03-07 23:40 448512 ----a-w- c:\windows\system32\html.iec
2012-03-07 23:40 . 2012-03-07 23:40 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-03-07 23:40 . 2012-03-07 23:40 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-03-07 23:40 . 2012-03-07 23:40 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-03-07 23:40 . 2012-03-07 23:40 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-07 23:40 . 2012-03-07 23:40 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-03-07 23:40 . 2012-03-07 23:40 222208 ----a-w- c:\windows\system32\msls31.dll
2012-03-07 23:40 . 2012-03-07 23:40 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-03-07 23:40 . 2012-03-07 23:40 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-03-07 23:40 . 2012-03-07 23:40 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-03-07 23:40 . 2012-03-07 23:40 160256 ----a-w- c:\windows\system32\wextract.exe
2012-03-07 23:40 . 2012-03-07 23:40 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-03-07 23:40 . 2012-03-07 23:40 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-03-07 23:40 . 2012-03-07 23:40 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-03-07 23:40 . 2012-03-07 23:40 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-03-07 23:40 . 2012-03-07 23:40 12288 ----a-w- c:\windows\system32\mshta.exe
2012-03-07 23:40 . 2012-03-07 23:40 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-03-07 23:40 . 2012-03-07 23:40 114176 ----a-w- c:\windows\system32\admparse.dll
2012-03-07 23:40 . 2012-03-07 23:40 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-03-07 23:40 . 2012-03-07 23:40 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-03-07 23:40 . 2012-03-07 23:40 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-03-03 16:15 . 2012-03-03 16:15 74703 ----a-w- c:\windows\SysWow64\mfc45.dll
2012-03-03 14:23 . 2012-03-03 14:23 27136 ------w- c:\windows\system32\bddel.exe
2012-03-01 09:04 . 2012-03-01 09:04 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-29 20:04 . 2012-02-29 20:04 540176 ----a-w- c:\programdata\1330543295.bdinstall.bin
2012-02-29 19:30 . 2012-02-29 19:30 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-29 19:30 . 2012-02-29 19:30 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-29 19:29 . 2012-02-29 19:29 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-29 19:29 . 2012-02-29 19:29 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-29 19:29 . 2012-02-29 19:29 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-29 19:27 . 2012-02-29 19:27 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-29 19:27 . 2012-02-29 19:27 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-29 19:26 . 2012-02-29 19:26 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-02-29 19:26 . 2012-02-29 19:26 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-02-29 19:26 . 2012-02-29 19:26 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-02-29 19:26 . 2012-02-29 19:26 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-02-29 19:26 . 2012-02-29 19:26 459232 ----a-w- c:\windows\system32\drivers\cng.sys
2012-02-29 19:26 . 2012-02-29 19:26 395776 ----a-w- c:\windows\system32\webio.dll
2012-02-29 19:26 . 2012-02-29 19:26 340992 ----a-w- c:\windows\system32\schannel.dll
2012-02-29 19:26 . 2012-02-29 19:26 314880 ----a-w- c:\windows\SysWow64\webio.dll
2012-02-29 19:26 . 2012-02-29 19:26 31232 ----a-w- c:\windows\system32\lsass.exe
2012-02-29 19:26 . 2012-02-29 19:26 29184 ----a-w- c:\windows\system32\sspisrv.dll
2012-02-29 19:26 . 2012-02-29 19:26 28160 ----a-w- c:\windows\system32\secur32.dll
2012-02-29 19:26 . 2012-02-29 19:26 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-02-29 19:26 . 2012-02-29 19:26 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-02-29 19:26 . 2012-02-29 19:26 152432 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-02-29 19:26 . 2012-02-29 19:26 1447936 ----a-w- c:\windows\system32\lsasrv.dll
2012-02-29 19:26 . 2012-02-29 19:26 136192 ----a-w- c:\windows\system32\sspicli.dll
2012-02-29 19:26 . 2012-02-29 19:26 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-02-29 19:26 . 2012-02-29 19:26 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-02-29 19:26 . 2012-02-29 19:26 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-02-29 19:26 . 2012-02-29 19:26 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-02-29 19:25 . 2012-02-29 19:25 77312 ----a-w- c:\windows\system32\packager.dll
2012-02-29 19:25 . 2012-02-29 19:25 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-02-29 19:24 . 2012-02-29 19:24 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-02-29 19:24 . 2012-02-29 19:24 2048 ----a-w- c:\windows\system32\tzres.dll
2012-02-29 19:24 . 2012-02-29 19:24 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-02-29 19:23 . 2012-02-29 19:23 723456 ----a-w- c:\windows\system32\EncDec.dll
2012-02-29 19:23 . 2012-02-29 19:23 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-02-29 19:21 . 2012-02-29 19:21 288640 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-02-29 19:21 . 2012-02-29 19:21 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-02-29 19:12 . 2012-02-29 19:12 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-02-29 19:12 . 2012-02-29 19:12 75776 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 72704 ----a-w- c:\windows\SysWow64\Mpeg2Data.ax
2012-02-29 19:12 . 2012-02-29 19:12 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-02-29 19:12 . 2012-02-29 19:12 59904 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-02-29 19:12 . 2012-02-29 19:12 288256 ----a-w- c:\windows\system32\MSNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 204288 ----a-w- c:\windows\SysWow64\MSNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-02-29 19:12 . 2012-02-29 19:12 104960 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-02-29 19:12 . 2012-02-29 19:12 861696 ----a-w- c:\windows\system32\oleaut32.dll
2012-02-29 19:12 . 2012-02-29 19:12 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2012-02-29 19:12 . 2012-02-29 19:12 331776 ----a-w- c:\windows\system32\oleacc.dll
2012-02-29 19:12 . 2012-02-29 19:12 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2012-02-29 19:10 . 2012-02-29 19:10 212992 ----a-w- c:\windows\system32\odbctrac.dll
2012-02-29 19:10 . 2012-02-29 19:10 163840 ----a-w- c:\windows\system32\odbccp32.dll
2012-02-29 19:10 . 2012-02-29 19:10 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll
2012-02-29 19:10 . 2012-02-29 19:10 106496 ----a-w- c:\windows\system32\odbccu32.dll
2012-02-29 19:10 . 2012-02-29 19:10 106496 ----a-w- c:\windows\system32\odbccr32.dll
2012-02-29 19:10 . 2012-02-29 19:10 319488 ----a-w- c:\windows\SysWow64\odbcjt32.dll
2012-02-29 19:10 . 2012-02-29 19:10 86016 ----a-w- c:\windows\SysWow64\odbccu32.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\via\viaudioi\vdeck\vdeck.exe" [2010-08-11 2472048]
"StartCCC"="c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe" [2012-02-14 636032]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2012-01-03 843712]
"Adobe Reader Speed Launcher"="c:\program files (x86)\adobe\reader 10.0\reader\reader_sl.exe" [2011-01-30 35736]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 10752]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 253088]
R3 bdsandbox;bdsandbox;c:\windows\system32\drivers\bdsandbox.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-04-07 19952]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-02-14 736104]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [x]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe [2011-11-02 263480]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-03-06 134920]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2010-09-26 724152]
S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2010-09-26 724152]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-11-17 3273552]
S2 RadeonPro Support Service;RadeonPro Support Service;c:\program files (x86)\RadeonPro\RadeonProSupport.exe [2011-02-10 12800]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-04-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 15:17]
.
2012-03-03 c:\windows\Tasks\ASOService.job
- c:\program files (x86)\Advanced System Optimizer 3\ASO3.exe [2012-03-03 18:23]
.
2012-04-14 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001Core.job
- c:\users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-12 11:25]
.
2012-04-15 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001UA.job
- c:\users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-12 11:25]
.
2012-04-15 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2012-04-14 21:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 135408 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2011-11-17 3994960]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe" [2011-03-15 499608]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
FF - ProfilePath - c:\users\Clorky\AppData\Roaming\Mozilla\Firefox\Profiles\nzoqllew.default\
FF - prefs.js: browser.startup.homepage - www.google.cz
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: extentions.y2layers.installId - 567c00ab-1858-4585-8dda-e3e6e7fc816e
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,TopRelatedTopics,BestVideoDownloader,
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
.
.
------- Asociace souborů -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{152C96EB-288E-4EDC-B7C6-D21F8250ADF3} - (no file)
ShellIconOverlayIdentifiers-{342DAA0B-D796-460D-8566-901E08A1CCAD} - (no file)
ShellIconOverlayIdentifiers-{57595DAE-1AE1-4D97-A49E-67CBB53B52DF} - (no file)
ShellIconOverlayIdentifiers-{33816773-98AE-4723-ADE0-EBE54C8B5A67} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mysql]
"ImagePath"="c:\users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\mysqld-nt --defaults-file=c:\users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\my.cnf mysql"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1365180198-3819917712-2369891476-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ca,88,93,ea,23,f9,36,80,af,e7,8c,9b,3f,44,58,fc,77,04,3d,15,f2,5c,9a,
b4,56,b9,5d,a8,c4,76,a3,75,e8,85,8e,a6,cd,a8,1e,2e,4b,e1,69,6e,14,98,2c,99,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-1365180198-3819917712-2369891476-1001\Software\SecuROM\License information*]
"datasecu"=hex:05,e1,cf,03,79,da,b9,b5,7a,58,86,bd,7b,91,11,58,39,96,0f,04,1f,
60,d7,cf,05,7a,e7,4e,ea,a8,42,70,9f,9a,f8,a7,a1,ad,d0,ca,ea,a2,4c,3d,85,e5,\
"rkeysecu"=hex:9d,18,c2,66,c4,3c,cc,22,3e,ff,2e,38,89,b9,73,55
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG15.00.00.01PROFESSIONAL"="CFE1CA2B0F975DAD4D9EB25DEA92878C93B8ECAB521C7EEA39E3EC839017D1EE4911C78A1B75336D1264B7FB6F9FC66F968BBADE0524058D78513DFD473F32958A115042A82F5C855CEE78493D596C54EAE309DE6B3D4E08CE9D0AB62A379E1F87A8B500CE9B70CA506F01C66C949CF307803AA240D7A599A2B3B0B7B4AEAB7038106C066A476E64950C7D0C5AD85C5B63955537031B3A52DC75AF222687D13E97F40EA79BF0364D5A5FC0C12863976B7E4984B9F2DF9F98EE352C2A02D8ED94A677564FC58B8F574DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D1407BA7FD869164D67949DB7CE019D40AA5C838FACAD88F720A3481AB483170CBD662E5E8C032449C738B75445831C8F294696B6C6A0AA54923A9C32A04E0C2B75CCF2B9AD6F35D1C873AB5A038B4258268F99A9AF8A4150AFB800BD4D824191C6920FBAE1153D071AB32DE81063C71B771C176494051BA079B8CBD29B1DE0DB7B8046AF5F74E18FE8920EA915A972A54FF51087B470BA5DC5D54C28015E4B8CAF61D40A6F4C8176B7AC96E4543F39ADB1A9F657E46E5681C12E439D86CA930851076860F1A1AB2AD724818B20CBCBC8FACDB5BA0DE6D8EF6A6565B249A90198244521EBD7BFA5FB751FFCAF5E380B7157F5A83EA905DF6B13A55C0B7A888FEAC176970BA7B2E7220C46AD870CB30D0AC83E9C11CB383F9CE297C3F1E035EE1294F4D4BE7CCA1E386B47286FB7301BD324C4D80817B2FC1054EC2ED2D24602015CA3D5AE039EA93DB9D4FAE50563B1F6952C151AC2EC543635579E3FC012E013ADE50EA300069F91EE24A10DAB4804FE191B7B641D22B2E22A91116BAA36570470A4E38A471FC67D586E11ACF49B755A02BC2D2605CFBA4FA8546FB0A491E3F6DFCB2FF6C44A1DAA16F130AE42E0A15DF3BE3EC2EEBAC2977BE09D8B594ABAF08A4E401EF5ADD2269E6FD923065DD5BFE9D43743E268563C42F96E9D06C5C359569D575A6C32CB6438ADDBBCC79B929BB0B593527E2633216EE62B2CFB321A00FAB52CA85004213B81767B51A2690EF06C9AC2C07001CC10C875921E1FFE8C950290E6AB5A9420E46A16EE5C45DAB02410C22981FE4DC7B3E9725402EA609FAF4DAFA7A8591BC67FB75EDFFDF4C21AFA67F29FAD80A1011EC1B41609EACE8AC690187E8B300D4D8D0327EFF686BD1A228FEEF080E0DA06C19311EE864186B839D1D2F25F542B987538462F30E6A9B6A7F982DE59A29518F875E36EF42386CAC76E6B7ED6CFF4C702989D263293272A016C7C1B3E58362FFE510E95EFD893131816730EC8C2AE2AE0390B50AEA29EE00401AE4FD4AB6475F36772D6B941B798B44CFE06AFDCE244A602779C77B8397C6B27F0186A570A4A5DC9"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
.
**************************************************************************
.
Celkový čas: 2012-04-15 10:55:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-15 08:54
ComboFix2.txt 2012-04-14 17:06
.
Před spuštěním: 213 603 340 288 bytes free
Po spuštění: 213 520 531 456 bytes free
.
- - End Of File - - 1826E600D476C5EBB63883FA9D6345A5

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod jaro3 » 15 dub 2012 11:07

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

KillAll::
File::
c:\programdata\1334420640.bdinstall.bin
c:\programdata\1334420635.bdinstall.bin
c:\programdata\1334420597.bdinstall.bin
c:\windows\system32\bddel.exe
c:\programdata\1330543295.bdinstall.bin
c:\windows\system32\DRIVERS\avchv.sys
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001UA.job
c:\users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe

Driver::
avchv

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Clorky » 15 dub 2012 11:10

Jdu na to, do 20 minut to tu máš.
Zatím ti moc děkuji za spolupráci.

Uživatelský avatar
Clorky
Moderátor / člen HW týmu
Master Level 8.5
Master Level 8.5
Příspěvky: 7032
Registrován: květen 10
Bydliště: Moravskoslezský kraj
Pohlaví: Muž
Stav:
Offline

Re: Log HJT

Příspěvekod Clorky » 15 dub 2012 11:20

Tady je CF.:

ComboFix 12-04-14.02 - Clorky 15.04.2012 11:12:12.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1033.18.4094.2800 [GMT 2:00]
Spuštěný z: c:\users\Clorky\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Clorky\Desktop\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\1330543295.bdinstall.bin"
"c:\programdata\1334420597.bdinstall.bin"
"c:\programdata\1334420635.bdinstall.bin"
"c:\programdata\1334420640.bdinstall.bin"
"c:\users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe"
"c:\windows\system32\bddel.exe"
"c:\windows\system32\DRIVERS\avchv.sys"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1330543295.bdinstall.bin
c:\programdata\1334420597.bdinstall.bin
c:\programdata\1334420635.bdinstall.bin
c:\programdata\1334420640.bdinstall.bin
c:\users\Clorky\AppData\Local\Facebook\Update\FacebookUpdate.exe
c:\windows\system32\bddel.exe
c:\windows\system32\DRIVERS\avchv.sys
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1365180198-3819917712-2369891476-1001UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_avchv
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-15 do 2012-04-15 )))))))))))))))))))))))))))))))
.
.
2012-04-15 09:14 . 2012-04-15 09:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-14 18:13 . 2012-04-14 18:13 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F2CC860-4B70-4C50-8576-AAB417E199B3}\offreg.dll
2012-04-14 16:41 . 2012-03-06 23:04 337240 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-04-14 16:41 . 2012-03-06 23:01 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-04-14 16:41 . 2012-03-06 23:04 141144 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-04-14 16:40 . 2012-03-06 23:03 258904 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-04-14 16:40 . 2012-03-06 23:02 53080 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-04-14 16:40 . 2012-03-06 23:02 28504 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-04-14 16:40 . 2012-03-06 23:01 59224 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-04-14 16:40 . 2012-03-06 23:04 819032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-04-14 16:40 . 2012-03-06 23:01 69976 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-04-14 16:40 . 2012-03-06 23:15 258520 ----a-w- c:\windows\system32\aswBoot.exe
2012-04-14 16:40 . 2012-02-23 14:54 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-04-14 16:40 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-04-14 16:40 . 2012-03-06 23:15 201352 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-04-14 16:40 . 2012-04-14 16:40 -------- d-----w- c:\programdata\AVAST Software
2012-04-14 16:40 . 2012-04-14 16:40 -------- d-----w- c:\program files\AVAST Software
2012-04-14 16:20 . 2012-04-14 16:20 -------- d-----w- c:\users\Clorky\AppData\Local\Adobe
2012-04-14 15:17 . 2012-04-14 15:17 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-14 13:38 . 2012-04-14 13:38 -------- d-----w- c:\programdata\BDLogging
2012-04-14 13:23 . 2012-04-14 13:23 -------- d-----w- c:\users\Clorky\AppData\Roaming\GlarySoft
2012-04-14 13:21 . 2012-04-14 13:21 -------- d-----w- c:\program files (x86)\Glary Utilities
2012-04-14 10:15 . 2012-04-14 10:27 -------- d-----w- c:\users\Clorky\AppData\Roaming\Bioshock
2012-04-14 09:54 . 2012-04-14 09:54 -------- d-----w- c:\users\Clorky\AppData\Roaming\Malwarebytes
2012-04-14 09:54 . 2012-04-14 09:54 -------- d-----w- c:\programdata\Malwarebytes
2012-04-14 09:54 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-14 09:54 . 2012-04-14 09:54 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-13 11:17 . 2012-04-13 11:17 -------- d-----w- c:\program files\Java
2012-04-13 11:09 . 2012-04-13 11:17 955848 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-04-13 11:05 . 2012-04-13 12:12 -------- d-----w- c:\users\Clorky\AppData\Roaming\.Nitrous
2012-04-13 08:53 . 2012-03-14 03:27 8669240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F2CC860-4B70-4C50-8576-AAB417E199B3}\mpengine.dll
2012-04-12 20:30 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 20:30 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-12 20:30 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-12 20:30 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-12 20:30 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-12 20:30 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-12 20:30 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-12 18:28 . 2012-04-12 18:28 -------- d-----w- c:\users\Clorky\AppData\Local\Irrational Games
2012-04-12 16:00 . 2012-04-14 18:50 -------- d-----w- c:\users\Clorky\AppData\Roaming\.minecraft
2012-04-12 11:25 . 2012-04-12 11:26 -------- d-----w- c:\users\Clorky\AppData\Local\Facebook
2012-04-09 17:38 . 2012-04-09 17:38 -------- d-----w- c:\program files (x86)\Convert AVI to MP4
2012-04-08 08:50 . 2012-04-08 08:50 -------- d-----w- c:\users\Clorky\AppData\Local\Rockstar Games
2012-04-07 22:02 . 2012-04-07 22:02 -------- d-----w- c:\program files (x86)\AviSynth 2.5
2012-04-07 18:15 . 2012-04-07 20:08 -------- d-----w- c:\users\Clorky\AppData\Roaming\TS3Client
2012-04-07 18:15 . 2012-04-07 18:15 -------- d-----w- c:\users\Clorky\AppData\Local\TeamSpeak 3 Client
2012-04-07 14:30 . 2012-04-07 14:31 -------- d-----w- c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2012-04-07 09:57 . 2012-04-07 09:57 -------- d-sh--w- c:\programdata\SecuROM
2012-04-07 09:57 . 2012-04-07 09:57 -------- d--h--r- c:\users\Clorky\AppData\Roaming\SecuROM
2012-04-07 09:46 . 2012-04-07 09:46 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-04-04 15:33 . 2004-04-18 21:42 733184 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iKernel.dll
2012-04-04 15:33 . 2004-04-18 21:40 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\ctor.dll
2012-04-04 15:33 . 2004-04-18 21:39 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iscript.dll
2012-04-04 15:33 . 2004-04-18 21:39 172032 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iuser.dll
2012-04-04 15:33 . 2004-04-18 21:39 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\DotNetInstaller.exe
2012-04-04 15:33 . 2012-04-04 15:33 180356 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iGdi.dll
2012-04-04 15:33 . 2012-04-04 15:33 303236 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\setup.dll
2012-03-31 21:29 . 2012-03-31 21:29 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2012-03-31 21:29 . 2012-03-31 21:29 -------- d-----w- c:\windows\SysWow64\AGEIA
2012-03-31 21:29 . 2012-03-31 21:29 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-03-31 15:46 . 2012-03-31 15:46 -------- d-----w- c:\program files (x86)\Nuclear Coffee
2012-03-31 11:19 . 2012-01-25 06:38 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-03-31 11:19 . 2012-01-25 06:38 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-31 10:33 . 2012-03-31 10:33 -------- d-----w- c:\users\Clorky\AppData\Local\Mumble
2012-03-31 09:51 . 2012-03-31 22:20 -------- d-----w- c:\users\Clorky\AppData\Roaming\Mumble
2012-03-31 09:50 . 2012-03-31 09:50 -------- d-----w- c:\program files (x86)\Mumble
2012-03-31 07:47 . 2004-01-11 22:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-03-31 07:47 . 2003-03-19 01:14 499712 ----a-w- c:\windows\system32\MSVCP71.DLL
2012-03-31 07:28 . 2012-03-31 07:28 -------- d-----w- c:\users\Clorky\AppData\Roaming\XRay Engine
2012-03-31 06:24 . 2012-03-31 06:24 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-03-29 13:43 . 2012-04-14 15:17 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-28 18:45 . 2012-03-28 18:45 -------- d-----w- c:\users\Clorky\AppData\Local\SKIDROW
2012-03-28 18:44 . 2012-03-28 18:44 -------- d-----w- c:\program files (x86)\Microsoft XNA
2012-03-27 13:32 . 2012-03-27 13:34 -------- d-----w- c:\users\Clorky\AppData\Local\SkyrimMTO
2012-03-26 19:43 . 2012-03-26 19:43 -------- d-----w- c:\program files\NVIDIA Corporation
2012-03-26 19:42 . 2012-03-26 19:42 61440 ----a-w- c:\windows\SysWow64\nvPhotoshopUtil.dll
2012-03-20 18:35 . 2012-03-20 18:35 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2012-03-20 18:35 . 2012-03-20 18:35 188548 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2012-03-20 18:35 . 2003-11-10 17:14 729088 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2012-03-20 18:35 . 2003-11-10 17:13 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2012-03-20 18:35 . 2003-11-10 17:12 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2012-03-20 18:35 . 2003-11-10 17:12 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2012-03-20 18:35 . 2003-11-10 17:11 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-03-17 10:24 . 2012-03-17 10:24 -------- d-----w- c:\users\Clorky\AppData\Roaming\DarksporeData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 15:17 . 2012-02-29 18:34 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-13 11:17 . 2012-02-29 20:39 839112 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-31 10:50 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-03-31 10:50 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-03-09 19:45 . 2012-03-09 19:45 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-07 23:40 . 2012-03-07 23:40 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-03-07 23:40 . 2012-03-07 23:40 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-03-07 23:40 . 2012-03-07 23:40 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-03-07 23:40 . 2012-03-07 23:40 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-03-07 23:40 . 2012-03-07 23:40 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-03-07 23:40 . 2012-03-07 23:40 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-03-07 23:40 . 2012-03-07 23:40 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-03-07 23:40 . 2012-03-07 23:40 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-03-07 23:40 . 2012-03-07 23:40 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-03-07 23:40 . 2012-03-07 23:40 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-03-07 23:40 . 2012-03-07 23:40 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-03-07 23:40 . 2012-03-07 23:40 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-03-07 23:40 . 2012-03-07 23:40 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-03-07 23:40 . 2012-03-07 23:40 448512 ----a-w- c:\windows\system32\html.iec
2012-03-07 23:40 . 2012-03-07 23:40 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-03-07 23:40 . 2012-03-07 23:40 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-03-07 23:40 . 2012-03-07 23:40 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-03-07 23:40 . 2012-03-07 23:40 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-07 23:40 . 2012-03-07 23:40 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-03-07 23:40 . 2012-03-07 23:40 222208 ----a-w- c:\windows\system32\msls31.dll
2012-03-07 23:40 . 2012-03-07 23:40 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-03-07 23:40 . 2012-03-07 23:40 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-03-07 23:40 . 2012-03-07 23:40 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-03-07 23:40 . 2012-03-07 23:40 160256 ----a-w- c:\windows\system32\wextract.exe
2012-03-07 23:40 . 2012-03-07 23:40 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-03-07 23:40 . 2012-03-07 23:40 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-03-07 23:40 . 2012-03-07 23:40 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-03-07 23:40 . 2012-03-07 23:40 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-03-07 23:40 . 2012-03-07 23:40 12288 ----a-w- c:\windows\system32\mshta.exe
2012-03-07 23:40 . 2012-03-07 23:40 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-03-07 23:40 . 2012-03-07 23:40 114176 ----a-w- c:\windows\system32\admparse.dll
2012-03-07 23:40 . 2012-03-07 23:40 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-03-07 23:40 . 2012-03-07 23:40 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-03-07 23:40 . 2012-03-07 23:40 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-03-03 16:15 . 2012-03-03 16:15 74703 ----a-w- c:\windows\SysWow64\mfc45.dll
2012-03-01 09:04 . 2012-03-01 09:04 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-29 19:30 . 2012-02-29 19:30 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-29 19:30 . 2012-02-29 19:30 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-29 19:29 . 2012-02-29 19:29 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-29 19:29 . 2012-02-29 19:29 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-29 19:29 . 2012-02-29 19:29 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-29 19:27 . 2012-02-29 19:27 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-29 19:27 . 2012-02-29 19:27 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-29 19:26 . 2012-02-29 19:26 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-02-29 19:26 . 2012-02-29 19:26 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-02-29 19:26 . 2012-02-29 19:26 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-02-29 19:26 . 2012-02-29 19:26 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-02-29 19:26 . 2012-02-29 19:26 459232 ----a-w- c:\windows\system32\drivers\cng.sys
2012-02-29 19:26 . 2012-02-29 19:26 395776 ----a-w- c:\windows\system32\webio.dll
2012-02-29 19:26 . 2012-02-29 19:26 340992 ----a-w- c:\windows\system32\schannel.dll
2012-02-29 19:26 . 2012-02-29 19:26 314880 ----a-w- c:\windows\SysWow64\webio.dll
2012-02-29 19:26 . 2012-02-29 19:26 31232 ----a-w- c:\windows\system32\lsass.exe
2012-02-29 19:26 . 2012-02-29 19:26 29184 ----a-w- c:\windows\system32\sspisrv.dll
2012-02-29 19:26 . 2012-02-29 19:26 28160 ----a-w- c:\windows\system32\secur32.dll
2012-02-29 19:26 . 2012-02-29 19:26 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-02-29 19:26 . 2012-02-29 19:26 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-02-29 19:26 . 2012-02-29 19:26 152432 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-02-29 19:26 . 2012-02-29 19:26 1447936 ----a-w- c:\windows\system32\lsasrv.dll
2012-02-29 19:26 . 2012-02-29 19:26 136192 ----a-w- c:\windows\system32\sspicli.dll
2012-02-29 19:26 . 2012-02-29 19:26 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-02-29 19:26 . 2012-02-29 19:26 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-02-29 19:26 . 2012-02-29 19:26 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-02-29 19:26 . 2012-02-29 19:26 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-02-29 19:25 . 2012-02-29 19:25 77312 ----a-w- c:\windows\system32\packager.dll
2012-02-29 19:25 . 2012-02-29 19:25 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-02-29 19:24 . 2012-02-29 19:24 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-02-29 19:24 . 2012-02-29 19:24 2048 ----a-w- c:\windows\system32\tzres.dll
2012-02-29 19:24 . 2012-02-29 19:24 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-02-29 19:23 . 2012-02-29 19:23 723456 ----a-w- c:\windows\system32\EncDec.dll
2012-02-29 19:23 . 2012-02-29 19:23 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-02-29 19:21 . 2012-02-29 19:21 288640 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-02-29 19:21 . 2012-02-29 19:21 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-02-29 19:12 . 2012-02-29 19:12 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-02-29 19:12 . 2012-02-29 19:12 75776 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 72704 ----a-w- c:\windows\SysWow64\Mpeg2Data.ax
2012-02-29 19:12 . 2012-02-29 19:12 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-02-29 19:12 . 2012-02-29 19:12 59904 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-02-29 19:12 . 2012-02-29 19:12 288256 ----a-w- c:\windows\system32\MSNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 204288 ----a-w- c:\windows\SysWow64\MSNP.ax
2012-02-29 19:12 . 2012-02-29 19:12 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-02-29 19:12 . 2012-02-29 19:12 104960 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-02-29 19:12 . 2012-02-29 19:12 861696 ----a-w- c:\windows\system32\oleaut32.dll
2012-02-29 19:12 . 2012-02-29 19:12 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2012-02-29 19:12 . 2012-02-29 19:12 331776 ----a-w- c:\windows\system32\oleacc.dll
2012-02-29 19:12 . 2012-02-29 19:12 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2012-02-29 19:10 . 2012-02-29 19:10 212992 ----a-w- c:\windows\system32\odbctrac.dll
2012-02-29 19:10 . 2012-02-29 19:10 163840 ----a-w- c:\windows\system32\odbccp32.dll
2012-02-29 19:10 . 2012-02-29 19:10 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll
2012-02-29 19:10 . 2012-02-29 19:10 106496 ----a-w- c:\windows\system32\odbccu32.dll
2012-02-29 19:10 . 2012-02-29 19:10 106496 ----a-w- c:\windows\system32\odbccr32.dll
2012-02-29 19:10 . 2012-02-29 19:10 319488 ----a-w- c:\windows\SysWow64\odbcjt32.dll
2012-02-29 19:10 . 2012-02-29 19:10 86016 ----a-w- c:\windows\SysWow64\odbccu32.dll
2012-02-29 19:10 . 2012-02-29 19:10 81920 ----a-w- c:\windows\SysWow64\odbccr32.dll
2012-02-29 19:10 . 2012-02-29 19:10 163840 ----a-w- c:\windows\SysWow64\odbctrac.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-15_08.52.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-29 17:26 . 2012-04-15 08:53 39744 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-15 08:53 34252 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-02-29 17:20 . 2012-04-15 08:53 9514 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1365180198-3819917712-2369891476-1001_UserData.bin
- 2012-04-15 08:51 . 2012-04-15 08:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-15 09:15 . 2012-04-15 09:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-15 08:51 . 2012-04-15 08:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-15 09:15 . 2012-04-15 09:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-04-15 08:50 316792 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-15 09:14 316792 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-02-29 20:21 . 2012-04-15 09:14 34448560 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1365180198-3819917712-2369891476-1001-12288.dat
- 2012-02-29 20:21 . 2012-04-15 08:50 34448560 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1365180198-3819917712-2369891476-1001-12288.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\via\viaudioi\vdeck\vdeck.exe" [2010-08-11 2472048]
"StartCCC"="c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe" [2012-02-14 636032]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2012-01-03 843712]
"Adobe Reader Speed Launcher"="c:\program files (x86)\adobe\reader 10.0\reader\reader_sl.exe" [2011-01-30 35736]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 10752]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 253088]
R3 bdsandbox;bdsandbox;c:\windows\system32\drivers\bdsandbox.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-04-07 19952]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-02-14 736104]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [x]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe [2011-11-02 263480]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-03-06 134920]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2010-09-26 724152]
S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2010-09-26 724152]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2011-11-17 3273552]
S2 RadeonPro Support Service;RadeonPro Support Service;c:\program files (x86)\RadeonPro\RadeonProSupport.exe [2011-02-10 12800]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-04-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 15:17]
.
2012-03-03 c:\windows\Tasks\ASOService.job
- c:\program files (x86)\Advanced System Optimizer 3\ASO3.exe [2012-03-03 18:23]
.
2012-04-15 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2012-04-14 21:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 135408 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2011-11-17 3994960]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe" [2011-03-15 499608]
"combofix"="c:\combofix\CF4662.3XE" [2010-11-20 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
FF - ProfilePath - c:\users\Clorky\AppData\Roaming\Mozilla\Firefox\Profiles\nzoqllew.default\
FF - prefs.js: browser.startup.homepage - www.google.cz
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: extentions.y2layers.installId - 567c00ab-1858-4585-8dda-e3e6e7fc816e
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,TopRelatedTopics,BestVideoDownloader,
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{152C96EB-288E-4EDC-B7C6-D21F8250ADF3} - (no file)
ShellIconOverlayIdentifiers-{342DAA0B-D796-460D-8566-901E08A1CCAD} - (no file)
ShellIconOverlayIdentifiers-{57595DAE-1AE1-4D97-A49E-67CBB53B52DF} - (no file)
ShellIconOverlayIdentifiers-{33816773-98AE-4723-ADE0-EBE54C8B5A67} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mysql]
"ImagePath"="c:\users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\mysqld-nt --defaults-file=c:\users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\my.cnf mysql"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1365180198-3819917712-2369891476-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ca,88,93,ea,23,f9,36,80,af,e7,8c,9b,3f,44,58,fc,77,04,3d,15,f2,5c,9a,
b4,56,b9,5d,a8,c4,76,a3,75,e8,85,8e,a6,cd,a8,1e,2e,4b,e1,69,6e,14,98,2c,99,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-1365180198-3819917712-2369891476-1001\Software\SecuROM\License information*]
"datasecu"=hex:05,e1,cf,03,79,da,b9,b5,7a,58,86,bd,7b,91,11,58,39,96,0f,04,1f,
60,d7,cf,05,7a,e7,4e,ea,a8,42,70,9f,9a,f8,a7,a1,ad,d0,ca,ea,a2,4c,3d,85,e5,\
"rkeysecu"=hex:9d,18,c2,66,c4,3c,cc,22,3e,ff,2e,38,89,b9,73,55
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG15.00.00.01PROFESSIONAL"="CFE1CA2B0F975DAD4D9EB25DEA92878C93B8ECAB521C7EEA39E3EC839017D1EE4911C78A1B75336D1264B7FB6F9FC66F968BBADE0524058D78513DFD473F32958A115042A82F5C855CEE78493D596C54EAE309DE6B3D4E08CE9D0AB62A379E1F87A8B500CE9B70CA506F01C66C949CF307803AA240D7A599A2B3B0B7B4AEAB7038106C066A476E64950C7D0C5AD85C5B63955537031B3A52DC75AF222687D13E97F40EA79BF0364D5A5FC0C12863976B7E4984B9F2DF9F98EE352C2A02D8ED94A677564FC58B8F574DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D1407BA7FD869164D67949DB7CE019D40AA5C838FACAD88F720A3481AB483170CBD662E5E8C032449C738B75445831C8F294696B6C6A0AA54923A9C32A04E0C2B75CCF2B9AD6F35D1C873AB5A038B4258268F99A9AF8A4150AFB800BD4D824191C6920FBAE1153D071AB32DE81063C71B771C176494051BA079B8CBD29B1DE0DB7B8046AF5F74E18FE8920EA915A972A54FF51087B470BA5DC5D54C28015E4B8CAF61D40A6F4C8176B7AC96E4543F39ADB1A9F657E46E5681C12E439D86CA930851076860F1A1AB2AD724818B20CBCBC8FACDB5BA0DE6D8EF6A6565B249A90198244521EBD7BFA5FB751FFCAF5E380B7157F5A83EA905DF6B13A55C0B7A888FEAC176970BA7B2E7220C46AD870CB30D0AC83E9C11CB383F9CE297C3F1E035EE1294F4D4BE7CCA1E386B47286FB7301BD324C4D80817B2FC1054EC2ED2D24602015CA3D5AE039EA93DB9D4FAE50563B1F6952C151AC2EC543635579E3FC012E013ADE50EA300069F91EE24A10DAB4804FE191B7B641D22B2E22A91116BAA36570470A4E38A471FC67D586E11ACF49B755A02BC2D2605CFBA4FA8546FB0A491E3F6DFCB2FF6C44A1DAA16F130AE42E0A15DF3BE3EC2EEBAC2977BE09D8B594ABAF08A4E401EF5ADD2269E6FD923065DD5BFE9D43743E268563C42F96E9D06C5C359569D575A6C32CB6438ADDBBCC79B929BB0B593527E2633216EE62B2CFB321A00FAB52CA85004213B81767B51A2690EF06C9AC2C07001CC10C875921E1FFE8C950290E6AB5A9420E46A16EE5C45DAB02410C22981FE4DC7B3E9725402EA609FAF4DAFA7A8591BC67FB75EDFFDF4C21AFA67F29FAD80A1011EC1B41609EACE8AC690187E8B300D4D8D0327EFF686BD1A228FEEF080E0DA06C19311EE864186B839D1D2F25F542B987538462F30E6A9B6A7F982DE59A29518F875E36EF42386CAC76E6B7ED6CFF4C702989D263293272A016C7C1B3E58362FFE510E95EFD893131816730EC8C2AE2AE0390B50AEA29EE00401AE4FD4AB6475F36772D6B941B798B44CFE06AFDCE244A602779C77B8397C6B27F0186A570A4A5DC9"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
.
**************************************************************************
.
Celkový čas: 2012-04-15 11:18:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-15 09:18
ComboFix2.txt 2012-04-15 08:55
ComboFix3.txt 2012-04-14 17:06
.
Před spuštěním: 213 506 781 184 bytes free
Po spuštění: 213 296 558 080 bytes free
.
- - End Of File - - 5221FEB7CDA75D8F222192B85BB4AF54

Tady HJT.:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:19:57, on 15.4.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
E:\Programy\Mozilla Firefox 4.0\firefox.exe
E:\Programy\Mozilla Firefox 4.0\plugin-container.exe
C:\Users\Clorky\Desktop\Download\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HDAudDeck] c:\program files (x86)\via\viaudioi\vdeck\vdeck.exe -r
O4 - HKLM\..\Run: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe" msrun
O4 - HKLM\..\Run: [Adobe ARM] c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] c:\program files (x86)\adobe\reader 10.0\reader\reader_sl.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Global Startup: AML Device Install.lnk = C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASO3DiskOptimizer - Systweak Inc., (www.systweak.com) - C:\Program Files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - C:\Users\Clorky\Desktop\lokal\Extremis\server\mysql\bin\mysqld-nt.exe (file missing)
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RadeonPro Support Service - Mr. John aka japamd - C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 6208 bytes

Jdu na aswMBR, potom dodám v dalším postu.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 91 hostů