Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-07-23.04 - Marek 24.07.2011 15:16:35.1.4 - x64
- Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.4094.2774 [GMT 2:00]
- Spuštěný z: c:\users\Marek\Downloads\ComboFix.exe
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((( Soubory vytvořené od 2011-06-24 do 2011-07-24 )))))))))))))))))))))))))))))))
- .
- .
- 2011-07-24 22:35 . 2011-07-24 12:42 -------- d-----w- c:\windows\Panther
- 2011-07-24 22:35 . 2011-07-24 22:35 -------- d-----w- C:\Boot
- 2011-07-24 22:35 . 2011-07-24 22:35 -------- d-----w- c:\windows\system32\OEM
- 2011-07-24 13:19 . 2011-07-24 13:19 0 ----a-w- c:\windows\ativpsrm.bin
- 2011-07-24 13:18 . 2011-07-24 13:18 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2011-07-24 13:15 . 2011-07-24 13:15 -------- d-----w- C:\32788R22FWJFW
- 2011-07-24 13:06 . 2011-07-24 13:06 -------- d-----w- c:\program files\Common Files\ATI Technologies
- 2011-07-24 13:06 . 2009-09-30 14:34 121872 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
- 2011-07-24 13:05 . 2009-10-02 03:39 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
- 2011-07-24 13:05 . 2011-07-24 13:07 -------- d-----w- c:\program files (x86)\ATI Technologies
- 2011-07-24 13:04 . 2011-07-24 13:07 -------- d-sh--w- c:\windows\Installer
- 2011-07-24 13:04 . 2011-07-24 13:04 -------- d--h--w- c:\programdata\CanonBJ
- 2011-07-24 13:04 . 2008-02-25 18:00 82944 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9I.DLL
- 2011-07-24 13:04 . 2008-02-25 18:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9I.DLL
- 2011-07-24 13:04 . 2008-02-25 18:00 279040 ----a-w- c:\windows\system32\CNMLM9I.DLL
- 2011-07-24 13:03 . 2011-07-24 13:07 -------- d-----w- c:\program files\ATI Technologies
- 2011-07-24 13:03 . 2011-07-24 13:03 -------- d-----w- c:\program files\ATI
- 2011-07-24 13:01 . 2011-07-20 07:44 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3B3B09A9-E40E-4991-BF19-6C1917BD0F93}\mpengine.dll
- 2011-07-24 13:01 . 2011-05-24 17:14 270720 ------w- c:\windows\system32\MpSigStub.exe
- 2011-07-24 12:57 . 2011-07-24 12:57 -------- d-----w- C:\rsit
- 2011-07-24 12:57 . 2011-07-24 12:57 -------- d-----w- c:\program files\trend micro
- 2011-07-24 12:47 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
- 2011-07-24 12:47 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
- 2011-07-24 12:43 . 2011-07-24 12:43 -------- d-----w- c:\users\Marek
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- .
- (((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-10-01 98304]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- .
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
- .
- .
- --- Ostatní služby/ovladače v paměti ---
- .
- *NewlyCreated* - DXGKRNL
- .
- Obsah adresáře 'Naplánované úlohy'
- .
- 2011-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1918143655-1119562807-2491148442-1001Core.job
- - c:\users\Marek\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-24 12:59]
- .
- 2011-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1918143655-1119562807-2491148442-1001UA.job
- - c:\users\Marek\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-24 12:59]
- .
- .
- --------- x86-64 -----------
- .
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Doplňkový sken -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- mLocal Page = c:\windows\SysWOW64\blank.htm
- TCP: DhcpNameServer = 62.129.50.20 85.135.32.100
- .
- .
- --------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Jiné spuštené procesy ------------------------
- .
- c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
- .
- **************************************************************************
- .
- Celkový čas: 2011-07-24 15:21:49 - počítač byl restartován
- ComboFix-quarantined-files.txt 2011-07-24 13:21
- .
- Před spuštěním: Volných bajtů: 982 745 649 152
- Po spuštění: Volných bajtů: 982 618 198 016
- .
- - - End Of File - - 4663B630537031B9735AA43A87EB3A17
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement