Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 13-08-28.02 - Michal 28.08.2013 23:11:19.2.6 - x64
- Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.8094.5781 [GMT 2:00]
- Spuštěný z: c:\users\Michal\Desktop\ComboFix.exe
- Použité ovládací přepínače :: c:\users\Michal\Desktop\CFScript.txt
- AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
- SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\program files (x86)\AskPartnerNetwork
- c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\APNSetup.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1031.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1033.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1034.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1036.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1040.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1041.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1043.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1045.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\1049.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\2070.mst
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\appdata\Mozilla\Firefox\Profiles\{DefaultProfilesFolder}\extensions\[email protected]
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\AskToolbarInstaller-12.3.0_CME-V7.msi
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\{Crx_Version}\Toolbar.crx
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\ToolbarCR.crx
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\Update.xml
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport.dll
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\apnmcp.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\searchhook.dll
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\ServiceLocator.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\SO.dll
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\toolbar.dll
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Toolbar.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\ToolbarPS.dll
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\UpdateManager.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\{PartnerID}\config.xml
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\ask-search.xml
- c:\program files (x86)\AskPartnerNetwork\Toolbar\CME-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\UpdateManager.exe
- c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\ask-search.xml
- c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\CME-V7\config.xml
- c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
- c:\program files (x86)\Common Files\Spigot
- c:\program files (x86)\Common Files\Spigot\GC\coupons_2.4.crx
- c:\program files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx
- c:\program files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx
- c:\program files (x86)\Common Files\Spigot\GC\saebay_1.0.crx
- c:\program files (x86)\Common Files\Spigot\Search Settings\baidu_ff.xml
- c:\program files (x86)\Common Files\Spigot\Search Settings\baidu_ie.xml
- c:\program files (x86)\Common Files\Spigot\Search Settings\config.ini
- c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1031.ini
- c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1033.ini
- c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1034.ini
- c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1036.ini
- c:\program files (x86)\Common Files\Spigot\Search Settings\Lang\res1040.ini
- c:\program files (x86)\Common Files\Spigot\Search Settings\searchcom_ff.xml
- c:\program files (x86)\Common Files\Spigot\Search Settings\searchcom_ie.xml
- c:\program files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
- c:\program files (x86)\Common Files\Spigot\Search Settings\SearchSettings64.exe
- c:\program files (x86)\Common Files\Spigot\Search Settings\wth164.dll
- c:\program files (x86)\Common Files\Spigot\Search Settings\wthx164.dll
- c:\program files (x86)\Common Files\Spigot\Search Settings\yahoo_ff.xml
- c:\program files (x86)\Common Files\Spigot\Search Settings\yahoo_ie.xml
- c:\program files (x86)\Common Files\Spigot\Search Settings\yandex_ff.xml
- c:\program files (x86)\Common Files\Spigot\Search Settings\yandex_ie.xml
- c:\programdata\APN
- c:\programdata\AskPartnerNetwork
- c:\programdata\AskPartnerNetwork\Toolbar\CME-V7\Updater\Config\Config.31.2.0.0-3.xml
- c:\programdata\AskPartnerNetwork\Toolbar\CME-V7\Updater\Response\Response.31.2.0.0-0.xml
- c:\users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\s72ydlav.default\extensions\[email protected]
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Service_APNMCP
- -------\Service_APNMCP
- .
- .
- ((((((((((((((((((((((((( Soubory vytvořené od 2013-07-28 do 2013-08-28 )))))))))))))))))))))))))))))))
- .
- .
- 2013-08-28 21:15 . 2013-08-28 21:15 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2013-08-28 20:17 . 2013-08-28 20:17 -------- d-----w- C:\rsit
- 2013-08-28 20:17 . 2013-08-28 20:17 -------- d-----w- c:\program files\trend micro
- 2013-08-27 20:33 . 2013-07-09 06:03 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe
- 2013-08-27 20:33 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
- 2013-08-27 20:33 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
- 2013-08-27 20:33 . 2013-07-09 05:54 1732032 ----a-w- c:\windows\system32\ntdll.dll
- 2013-08-27 20:33 . 2013-07-09 05:53 243712 ----a-w- c:\windows\system32\wow64.dll
- 2013-08-27 20:33 . 2013-07-09 04:53 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
- 2013-08-27 20:33 . 2013-07-09 02:49 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
- 2013-08-27 20:33 . 2013-07-09 04:52 5120 ----a-w- c:\windows\SysWow64\wow32.dll
- 2013-08-27 20:33 . 2013-07-09 02:49 25600 ----a-w- c:\windows\SysWow64\setup16.exe
- 2013-08-27 20:33 . 2013-07-09 02:49 7680 ----a-w- c:\windows\SysWow64\instnm.exe
- 2013-08-27 20:33 . 2013-07-09 02:49 2048 ----a-w- c:\windows\SysWow64\user.exe
- 2013-08-27 19:35 . 2013-08-27 19:35 -------- d-----w- c:\programdata\Rockstar Games
- 2013-08-27 19:33 . 2013-08-27 19:33 -------- d-----w- c:\program files (x86)\Rockstar Games
- 2013-08-27 07:27 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
- 2013-08-27 07:27 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
- 2013-08-27 07:27 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BC574FC6-9B35-48F0-A326-3A67809E1F7E}\mpengine.dll
- 2013-08-27 07:26 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
- 2013-08-27 07:26 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
- 2013-08-26 21:28 . 2013-08-26 21:28 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
- 2013-08-26 07:15 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
- 2013-08-26 07:14 . 2013-06-15 04:32 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
- 2013-08-26 07:12 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
- 2013-08-26 07:12 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
- 2013-08-25 23:02 . 2013-08-25 23:02 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
- 2013-08-25 23:01 . 2013-08-25 23:01 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
- 2013-08-25 22:37 . 2013-08-25 22:37 -------- d-----w- c:\program files (x86)\Seznam.cz
- 2013-08-25 22:21 . 2013-08-25 22:40 -------- d-----w- c:\program files (x86)\Common Files\Steam
- 2013-08-25 21:07 . 2013-08-25 21:07 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
- 2013-08-25 21:07 . 2013-08-25 21:07 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
- 2013-08-25 21:06 . 2013-08-25 22:34 -------- d-----w- c:\programdata\DAEMON Tools Lite
- 2013-08-25 19:22 . 2013-08-28 19:45 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
- 2013-08-25 19:22 . 2013-08-25 19:22 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
- 2013-08-25 19:19 . 2013-08-25 19:19 -------- d-----w- c:\programdata\EA Core
- 2013-08-25 19:19 . 2013-08-28 17:51 -------- d-----w- c:\programdata\EA Logs
- 2013-08-25 18:46 . 2013-08-25 18:46 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
- 2013-08-25 18:46 . 2013-08-28 19:45 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
- 2013-08-25 18:46 . 2013-08-28 19:45 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
- 2013-08-25 18:46 . 2013-08-25 19:44 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
- 2013-08-25 18:44 . 2008-10-15 04:22 519000 ----a-w- c:\windows\system32\d3dx10_40.dll
- 2013-08-25 14:46 . 2013-08-25 14:46 -------- d-----w- c:\programdata\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
- 2013-08-25 14:46 . 2013-08-25 14:46 -------- d-----w- c:\program files (x86)\IObit Apps Toolbar
- 2013-08-25 14:46 . 2013-08-25 14:46 -------- d-----w- c:\program files (x86)\Application Updater
- 2013-08-25 14:45 . 2013-08-25 14:46 -------- d-----w- c:\programdata\IObit
- 2013-08-25 14:45 . 2013-08-25 14:45 -------- d-----w- c:\program files (x86)\IObit
- 2013-08-25 13:07 . 2013-05-09 08:59 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
- 2013-08-25 13:07 . 2013-08-25 13:08 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys
- 2013-08-25 13:07 . 2013-05-09 08:59 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
- 2013-08-25 13:07 . 2013-05-09 08:59 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys
- 2013-08-25 13:07 . 2013-08-25 13:08 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys
- 2013-08-25 13:07 . 2013-08-25 13:08 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
- 2013-08-25 13:07 . 2013-05-09 08:59 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
- 2013-08-25 13:07 . 2013-05-09 08:59 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
- 2013-08-25 13:06 . 2013-05-09 08:58 41664 ----a-w- c:\windows\avastSS.scr
- 2013-08-25 13:04 . 2013-08-25 13:04 -------- d-----w- c:\program files\TeamSpeak 3 Client
- 2013-08-25 12:57 . 2013-08-28 16:38 -------- d-----w- c:\programdata\Electronic Arts
- 2013-08-25 12:57 . 2013-08-25 12:59 -------- d-----w- c:\programdata\Origin
- 2013-08-25 12:52 . 2008-07-31 08:41 68616 ----a-w- c:\windows\SysWow64\XAPOFX1_1.dll
- 2013-08-25 12:52 . 2008-07-31 08:40 509448 ----a-w- c:\windows\SysWow64\XAudio2_2.dll
- 2013-08-25 12:52 . 2008-07-12 06:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
- 2013-08-25 12:52 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
- 2013-08-25 12:52 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
- 2013-08-25 12:52 . 2013-08-25 12:52 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
- 2013-08-25 12:49 . 2013-08-28 17:54 -------- d-----w- c:\programdata\PMB Files
- 2013-08-25 12:49 . 2013-08-25 12:49 -------- d-----w- c:\program files (x86)\Pando Networks
- 2013-08-25 12:45 . 2013-08-25 12:45 -------- d-----w- c:\program files (x86)\Common Files\Skype
- 2013-08-25 12:45 . 2013-08-25 12:45 -------- d-----r- c:\program files (x86)\Skype
- 2013-08-25 12:45 . 2013-08-25 12:45 -------- d-----w- c:\programdata\Skype
- 2013-08-25 12:37 . 2013-08-25 12:37 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2013-08-25 12:37 . 2013-08-25 12:37 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
- 2013-08-25 12:37 . 2013-08-25 12:37 -------- d-----w- c:\windows\SysWow64\Macromed
- 2013-08-25 12:37 . 2013-08-25 12:37 -------- d-----w- c:\windows\system32\Macromed
- 2013-08-25 12:29 . 2013-08-25 12:29 -------- d-----w- c:\windows\system32\SPReview
- 2013-08-25 12:06 . 2010-11-20 03:32 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\rdpwd.sys.mui
- 2013-08-25 12:06 . 2010-11-20 03:26 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\tsusbflt.sys.mui
- 2013-08-25 12:06 . 2010-11-20 03:32 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
- 2013-08-25 12:06 . 2010-11-20 03:32 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
- 2013-08-25 12:03 . 2013-08-25 12:03 -------- d-----w- c:\windows\system32\EventProviders
- 2013-08-20 18:46 . 2013-08-20 18:46 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
- 2013-08-20 18:40 . 2013-08-20 18:40 -------- d-s---w- c:\windows\SysWow64\Microsoft
- 2013-08-20 18:17 . 2013-08-20 18:17 -------- d-----w- c:\windows\SysWow64\Wat
- 2013-08-20 18:17 . 2013-08-20 18:17 -------- d-----w- c:\windows\system32\Wat
- 2013-08-20 17:38 . 2013-05-09 08:58 287840 ----a-w- c:\windows\system32\aswBoot.exe
- 2013-08-20 17:23 . 2013-08-20 17:23 -------- d-----w- c:\programdata\Ashampoo
- 2013-08-20 17:23 . 2013-08-20 17:23 -------- d-----w- c:\program files (x86)\Ashampoo
- 2013-08-20 17:20 . 2013-08-25 13:06 -------- d-----w- c:\program files\AVAST Software
- 2013-08-20 17:19 . 2013-08-25 13:06 -------- d-----w- c:\programdata\AVAST Software
- 2013-08-20 17:14 . 2012-07-26 07:40 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
- 2013-08-20 17:14 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
- 2013-08-20 17:14 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
- 2013-08-20 17:14 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
- 2013-08-20 17:10 . 2013-08-20 17:10 -------- d-----w- c:\program files\Totalcmd
- 2013-08-20 17:04 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
- 2013-08-20 17:02 . 2013-08-20 17:03 -------- d-----w- c:\windows\system32\MRT
- 2013-08-20 16:48 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
- 2013-08-20 16:48 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
- 2013-08-20 16:48 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
- 2013-08-20 16:48 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
- 2013-08-20 16:48 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
- 2013-08-20 16:48 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
- 2013-08-20 16:47 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
- 2013-08-20 16:47 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
- 2013-08-20 16:47 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
- 2013-08-20 16:47 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
- 2013-08-20 16:47 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
- 2013-08-20 16:47 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
- 2013-08-20 16:47 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
- 2013-08-20 16:41 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
- 2013-08-20 16:41 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
- 2013-08-20 16:41 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
- 2013-08-20 16:41 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
- 2013-08-20 16:41 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
- 2013-08-20 16:35 . 2012-11-30 05:45 362496 ----a-w- c:\windows\system32\wow64win.dll
- 2013-08-20 16:34 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
- 2013-08-20 16:34 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys
- 2013-08-20 16:34 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
- 2013-08-20 16:34 . 2011-11-17 05:35 314880 ----a-w- c:\windows\SysWow64\webio.dll
- 2013-08-20 16:34 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
- 2013-08-20 16:34 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
- 2013-08-20 16:32 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
- 2013-08-20 16:31 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
- 2013-08-20 16:18 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
- 2013-08-20 16:18 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2013-08-26 21:29 . 2013-08-26 21:29 247296 ----a-w- c:\windows\system32\webcheck.dll
- 2013-08-26 21:29 . 2013-08-26 21:29 204800 ----a-w- c:\windows\SysWow64\webcheck.dll
- 2013-08-25 12:25 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
- 2013-08-25 12:25 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
- 2013-07-09 04:45 . 2013-08-27 20:33 44032 ----a-w- c:\windows\apppatch\acwow64.dll
- .
- .
- (((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
- REGEDIT4
- .
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
- "{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll" [2013-08-08 1356096]
- .
- [HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
- 2013-08-08 17:33 1356096 ----a-w- c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
- "{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files (x86)\IObit Apps Toolbar\IE\7.4\iobitappsToolbarIE.dll" [2013-08-08 1356096]
- .
- [HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-06-05 17:17 130736 ----a-w- c:\users\Michal\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-06-05 17:17 130736 ----a-w- c:\users\Michal\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-06-05 17:17 130736 ----a-w- c:\users\Michal\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Advanced SystemCare 6"="c:\program files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" [2013-04-18 491840]
- "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
- "Steam"="d:\steam\Steam.exe" [2013-07-26 1807272]
- "cz.seznam.software.autoupdate"="c:\users\Michal\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
- "cz.seznam.software.szndesktop"="c:\users\Michal\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
- "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
- "seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2013-05-16 1062472]
- .
- c:\users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- Dropbox.lnk - c:\users\Michal\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-6-5 27370808]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
- "LoadAppInit_DLLs"=1 (0x1)
- .
- R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
- R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
- S0 aswRvrt;aswRvrt; [x]
- S0 aswVmm;aswVmm; [x]
- S1 aswSnx;aswSnx; [x]
- S1 aswSP;aswSP; [x]
- S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
- S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
- S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
- S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
- S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [x]
- S2 aswFsBlk;aswFsBlk; [x]
- S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
- S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
- S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
- S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
- S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
- S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
- .
- .
- --- Ostatní služby/ovladače v paměti ---
- .
- *NewlyCreated* - WS2IFSL
- .
- Obsah adresáře 'Naplánované úlohy'
- .
- 2013-08-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-25 12:37]
- .
- .
- --------- X64 Entries -----------
- .
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
- @="{472083B0-C522-11CF-8763-00608CC02F24}"
- [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
- 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-06-05 17:17 164016 ----a-w- c:\users\Michal\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-06-05 17:17 164016 ----a-w- c:\users\Michal\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-06-05 17:17 164016 ----a-w- c:\users\Michal\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
- @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-06-05 17:17 164016 ----a-w- c:\users\Michal\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
- .
- ------- Doplňkový sken -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = hxxp://www.seznam.cz/?clid=12454
- mLocal Page = c:\windows\SysWOW64\blank.htm
- TCP: DhcpNameServer = 192.168.1.1
- FF - ProfilePath - c:\users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\s72ydlav.default\
- FF - prefs.js: browser.startup.homepage - hxxps://www.google.cz/
- FF - ExtSQL: 2013-06-30 10:44; [email protected]; c:\users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\s72ydlav.default\extensions\[email protected]
- FF - ExtSQL: 2013-08-25 15:06; [email protected]; c:\program files\AVAST Software\Avast\WebRep\FF
- FF - ExtSQL: 2013-08-25 16:46; [email protected]; c:\program files (x86)\IObit Apps Toolbar\FF
- FF - ExtSQL: 2013-08-25 18:45; [email protected]; c:\users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\s72ydlav.default\extensions\[email protected]
- FF - ExtSQL: 2013-08-26 00:37; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\s72ydlav.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- FF - ExtSQL: 2013-08-27 22:19; [email protected]; c:\users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\s72ydlav.default\extensions\[email protected]
- .
- - - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
- .
- Wow6432Node-HKLM-Run-<NO NAME> - (no file)
- .
- .
- .
- --------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Jiné spuštené procesy ------------------------
- .
- c:\program files\AVAST Software\Avast\AvastSvc.exe
- c:\windows\DAODx.exe
- c:\program files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
- c:\windows\SysWOW64\PnkBstrA.exe
- c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
- .
- **************************************************************************
- .
- Celkový čas: 2013-08-28 23:20:44 - počítač byl restartován
- ComboFix-quarantined-files.txt 2013-08-28 21:20
- ComboFix2.txt 2013-08-28 20:42
- .
- Před spuštěním: Volných bajtů: 454 203 039 744
- Po spuštění: Volných bajtů: 453 620 641 792
- .
- - - End Of File - - 02631836F7BC8A9CBA40BD8970BE73F8
- A36C5E4F47E84449FF07ED3517B43A31
Advertisement
Add Comment
Please, Sign In to add comment