ComboFix 10-03-09.04 - Andrejko . 03. 2010 23:04:46.8.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3069.2316 [GMT 1:00]
Running from: c:\users\Andrejko\Downloads\ComboFix.exe
Command switches used :: c:\users\Andrejko\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Panda Security
c:\program files\Panda Security\ActiveScan 2.0\apicr.dll
c:\program files\Panda Security\ActiveScan 2.0\as2auditor.dll
c:\program files\Panda Security\ActiveScan 2.0\as2data.dll
c:\program files\Panda Security\ActiveScan 2.0\as2guiie.dll
c:\program files\Panda Security\ActiveScan 2.0\as2inst.dll
c:\program files\Panda Security\ActiveScan 2.0\as2scanner.dll
c:\program files\Panda Security\ActiveScan 2.0\as2stubie.dll
c:\program files\Panda Security\ActiveScan 2.0\as2uninst.exe
c:\program files\Panda Security\ActiveScan 2.0\asmdat.dll
c:\program files\Panda Security\ActiveScan 2.0\avdetect.ini
c:\program files\Panda Security\ActiveScan 2.0\ee366d2b2e4ede8287de879e85a0dcc2KRN_DATA
c:\program files\Panda Security\ActiveScan 2.0\ee366d2b2e4ede8287de879e85a0dcc2PSK_NM
c:\program files\Panda Security\ActiveScan 2.0\ee366d2b2e4ede8287de879e85a0dcc2PSK_NM2
c:\program files\Panda Security\ActiveScan 2.0\firewalldetect.ini
c:\program files\Panda Security\ActiveScan 2.0\kreexent.dll
c:\program files\Panda Security\ActiveScan 2.0\libcomm.dll
c:\program files\Panda Security\ActiveScan 2.0\libxml2.dll
c:\program files\Panda Security\ActiveScan 2.0\mapvfile.dll
c:\program files\Panda Security\ActiveScan 2.0\memvfile.dll
c:\program files\Panda Security\ActiveScan 2.0\microsoft.vc80.crt.manifest
c:\program files\Panda Security\ActiveScan 2.0\minicrypto.dll
c:\program files\Panda Security\ActiveScan 2.0\msvcp80.dll
c:\program files\Panda Security\ActiveScan 2.0\msvcr71.dll
c:\program files\Panda Security\ActiveScan 2.0\msvcr80.dll
c:\program files\Panda Security\ActiveScan 2.0\nanocache.fil2
c:\program files\Panda Security\ActiveScan 2.0\npwrapper.dll
c:\program files\Panda Security\ActiveScan 2.0\pav.sig
c:\program files\Panda Security\ActiveScan 2.0\pavboot.sys
c:\program files\Panda Security\ActiveScan 2.0\pavboot64.sys
c:\program files\Panda Security\ActiveScan 2.0\pavexcom.dll
c:\program files\Panda Security\ActiveScan 2.0\pavoe.dll
c:\program files\Panda Security\ActiveScan 2.0\pavsddl.dll
c:\program files\Panda Security\ActiveScan 2.0\pavvt.dll
c:\program files\Panda Security\ActiveScan 2.0\pavvts.dat
c:\program files\Panda Security\ActiveScan 2.0\pskads.dll
c:\program files\Panda Security\ActiveScan 2.0\pskahk.dll
c:\program files\Panda Security\ActiveScan 2.0\pskalloc.dll
c:\program files\Panda Security\ActiveScan 2.0\pskas.dll
c:\program files\Panda Security\ActiveScan 2.0\pskavs.dll
c:\program files\Panda Security\ActiveScan 2.0\pskcmp.dll
c:\program files\Panda Security\ActiveScan 2.0\pskfss.dll
c:\program files\Panda Security\ActiveScan 2.0\pskhtml.dll
c:\program files\Panda Security\ActiveScan 2.0\pskmdfs.dll
c:\program files\Panda Security\ActiveScan 2.0\pskmfs.dll
c:\program files\Panda Security\ActiveScan 2.0\psknc.dll
c:\program files\Panda Security\ActiveScan 2.0\pskpack.dll
c:\program files\Panda Security\ActiveScan 2.0\pskqhs.dll
c:\program files\Panda Security\ActiveScan 2.0\pskscs.dll
c:\program files\Panda Security\ActiveScan 2.0\pskutil.dll
c:\program files\Panda Security\ActiveScan 2.0\pskvfile.dll
c:\program files\Panda Security\ActiveScan 2.0\pskvfs.dll
c:\program files\Panda Security\ActiveScan 2.0\pskvm.dll
c:\program files\Panda Security\ActiveScan 2.0\psnden.dll
c:\program files\Panda Security\ActiveScan 2.0\psndsk.dll
c:\program files\Panda Security\ActiveScan 2.0\psnengav.dll
c:\program files\Panda Security\ActiveScan 2.0\psnengav.nsc
c:\program files\Panda Security\ActiveScan 2.0\psnfc.dll
c:\program files\Panda Security\ActiveScan 2.0\psnglkntex.dll
c:\program files\Panda Security\ActiveScan 2.0\psnhsh.dll
c:\program files\Panda Security\ActiveScan 2.0\psnkrnl.dll
c:\program files\Panda Security\ActiveScan 2.0\psnxprs.dll
c:\program files\Panda Security\ActiveScan 2.0\psqmgr.dll
c:\program files\Panda Security\ActiveScan 2.0\psqstore\Invent.QCF
c:\program files\Panda Security\ActiveScan 2.0\psqstore\Invent.QCF.ext
c:\program files\Panda Security\ActiveScan 2.0\psqstore\PSQ.CFG
c:\program files\Panda Security\ActiveScan 2.0\pssarf.dll
c:\program files\Panda Security\ActiveScan 2.0\psscan.dll
c:\program files\Panda Security\ActiveScan 2.0\psscoms.dll
c:\program files\Panda Security\ActiveScan 2.0\psscpu.dll
c:\program files\Panda Security\ActiveScan 2.0\pssdet.dll
c:\program files\Panda Security\ActiveScan 2.0\psspa.dll
c:\program files\Panda Security\ActiveScan 2.0\pssqem.dll
c:\program files\Panda Security\ActiveScan 2.0\pssuts.dll
c:\program files\Panda Security\ActiveScan 2.0\pssyschk.dll
c:\program files\Panda Security\ActiveScan 2.0\putczip.dll
c:\program files\Panda Security\ActiveScan 2.0\rkpavproc.sys
c:\program files\Panda Security\ActiveScan 2.0\rkpavproc64.sys
c:\program files\Panda Security\ActiveScan 2.0\scremlsp.exe
c:\program files\Panda Security\ActiveScan 2.0\vplatdis.dll
c:\program files\Panda Security\ActiveScan 2.0\vplatprc.dll
c:\program files\TrojanHunter 5.1
c:\program files\TrojanHunter 5.1\Debug.log
c:\program files\TrojanHunter 5.1\IL.ini
c:\program files\TrojanHunter 5.1\Scan Reports\2010-03-09_0535.txt
c:\programdata\Norton
c:\programdata\Norton\00000082\00000105\0000034c\cltLMS1.dat
c:\programdata\Norton\00000082\00000105\0000034c\cltLMS2.dat
c:\programdata\Norton\00000082\00000105\cltupgrade.dat
c:\programdata\Norton\00000082\00000105\key.txt
c:\programdata\Norton\symdata.xml
c:\users\Andrejko\AppData\Roaming\TrojanHunter
c:\users\Andrejko\AppData\Roaming\TrojanHunter\TreeState.dat
.
((((((((((((((((((((((((( Files Created from 2010-02-09 to 2010-03-09 )))))))))))))))))))))))))))))))
.
2010-03-09 22:13 . 2010-03-09 22:13 -------- d-----w- c:\users\Andrejko\AppData\Local\temp
2010-03-09 22:13 . 2010-03-09 22:13 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-03-09 22:13 . 2010-03-09 22:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-09 21:57 . 2010-03-09 21:57 318976 ----a-w- c:\windows\system32\CF30350.exe
2010-03-09 19:02 . 2010-03-09 19:06 -------- d-----w- c:\program files\trend micro
2010-03-09 19:02 . 2010-03-09 19:03 -------- d-----w- C:\rsit
2010-03-09 14:11 . 2010-03-09 14:11 80400 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2010-03-09 14:11 . 2010-03-09 14:11 80400 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2010-03-09 13:55 . 2010-03-09 13:55 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2010-03-09 13:55 . 2010-03-09 13:55 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2010-03-09 13:54 . 2010-03-09 13:54 -------- d-----w- c:\program files\Kaspersky Lab
2010-03-09 13:46 . 2010-03-09 13:46 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-03-09 05:42 . 2010-03-09 05:42 -------- d-----w- c:\program files\AVG
2010-03-09 00:02 . 2010-03-09 00:02 -------- d-----w- c:\program files\Enigma Software Group
2010-03-08 22:23 . 2010-03-08 22:23 -------- d-----w- c:\users\Andrejko\AppData\Local\ESET
2010-03-08 21:38 . 2010-03-09 21:10 -------- d-----w- c:\programdata\Kaspersky Lab
2010-03-08 16:31 . 2010-03-08 16:31 16925 ----a-w- c:\windows\DIIUnin.dat
2010-03-08 16:31 . 2010-03-08 16:31 2829 ----a-w- c:\windows\DIIUnin.pif
2010-03-08 16:31 . 2010-03-08 16:31 94208 ----a-w- c:\windows\DIIUnin.exe
2010-03-08 16:29 . 2010-03-08 23:41 -------- d-----w- c:\program files\Diablo II
2010-03-07 22:20 . 2010-02-12 10:32 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-03-04 12:33 . 2010-03-04 12:33 -------- d-----w- c:\programdata\PC Suite
2010-03-04 12:33 . 2010-03-04 12:33 -------- d-----w- c:\users\Andrejko\AppData\Roaming\PC Suite
2010-03-04 12:28 . 2010-03-04 12:28 -------- d-----w- c:\programdata\Nokia
2010-03-04 12:24 . 2010-03-04 12:24 -------- d-----w- c:\program files\DIFX
2010-03-04 12:24 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-03-04 12:24 . 2010-03-04 12:24 -------- d-----w- c:\program files\PC Connectivity Solution
2010-03-04 12:20 . 2009-12-30 10:30 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-03-04 12:20 . 2010-03-04 12:20 -------- d-----w- c:\program files\Nokia
2010-03-04 12:20 . 2010-03-04 12:20 -------- d-----w- c:\program files\Common Files\Nokia
2010-03-04 12:20 . 2010-03-02 14:59 34814832 ----a-w- c:\programdata\Installations\{D043E0F8-5EFA-4102-A863-08F39D9DF2F4}\NokiaSoftwareUpdaterSetup_sk.exe
2010-03-04 12:18 . 2010-03-04 12:18 36864 ----a-w- c:\programdata\Installations\{D043E0F8-5EFA-4102-A863-08F39D9DF2F4}\Installer\CommonCustomActions\Sleep.exe
2010-03-04 12:18 . 2010-03-04 12:18 3351812 ----a-w- c:\programdata\Installations\{D043E0F8-5EFA-4102-A863-08F39D9DF2F4}\Installer\CommonCustomActions\msxml6Exec.exe
2010-03-04 12:18 . 2010-03-04 12:18 3203453 ----a-w- c:\programdata\Installations\{D043E0F8-5EFA-4102-A863-08F39D9DF2F4}\Installer\CommonCustomActions\vcredistExec.exe
2010-03-04 12:18 . 2010-03-04 12:18 -------- d-----w- c:\programdata\Installations
2010-03-03 08:31 . 2010-03-03 08:31 -------- d-----w- C:\VJVod_Cache
2010-02-25 11:59 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-25 11:59 . 2010-02-25 11:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 11:59 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-24 12:42 . 2010-01-23 09:26 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-24 12:29 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 12:29 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll
2010-02-24 12:29 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 12:29 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 12:29 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-02-24 12:29 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 12:29 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 12:29 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 12:29 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-02-24 12:29 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-02-24 12:29 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-02-24 12:29 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-02-24 10:23 . 2010-02-24 10:28 -------- d-----w- c:\program files\Wise Registry Cleaner
2010-02-24 10:12 . 2010-02-24 10:12 -------- d-----w- c:\program files\VS Revo Group
2010-02-24 07:42 . 2010-03-09 05:41 -------- d-----w- c:\program files\ESET
2010-02-23 15:20 . 2010-02-24 08:16 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-17 11:39 . 2010-02-17 11:39 -------- d-----w- c:\program files\Ubisoft
2010-02-10 08:48 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-10 08:48 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-10 08:48 . 2009-12-08 20:01 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-10 08:48 . 2009-12-08 20:01 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-09 19:10 . 2008-11-20 21:10 -------- d-----w- c:\programdata\Apple Computer
2010-03-09 13:49 . 2009-02-24 19:42 -------- d-----w- c:\users\Andrejko\AppData\Roaming\SUPERAntiSpyware.com
2010-03-09 13:49 . 2008-10-22 13:45 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-09 13:49 . 2009-02-24 19:42 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-03-09 06:13 . 2009-11-06 12:43 -------- d-----w- c:\program files\Stylish Profile
2010-03-08 23:41 . 2008-10-27 12:19 -------- d-----w- c:\program files\Common Files\Skype
2010-03-08 21:18 . 2008-04-24 06:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-08 20:02 . 2009-04-22 10:09 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-03-05 21:33 . 2008-10-22 13:53 1 ----a-w- c:\users\Andrejko\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-03-04 12:33 . 2010-03-04 12:33 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-03-03 09:39 . 2009-07-23 20:21 680 ----a-w- c:\users\Andrejko\AppData\Local\d3d9caps.dat
2010-03-02 20:58 . 2008-11-28 14:33 -------- d-----w- c:\users\Andrejko\AppData\Roaming\dvdcss
2010-02-25 05:24 . 2009-04-23 18:34 130448 ----a-w- c:\users\Andrejko\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 22:58 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2010-02-24 10:41 . 2008-05-14 05:57 -------- d-----w- c:\program files\Microsoft Works
2010-02-13 21:11 . 2009-11-26 09:43 -------- d-----w- c:\program files\Activision
2010-02-11 21:41 . 2010-01-13 00:43 -------- d-----w- c:\programdata\Media Center Programs
2010-02-11 08:21 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-10 21:30 . 2008-04-24 07:18 -------- d-----w- c:\program files\Google
2010-01-31 10:30 . 2010-01-30 21:43 -------- d-----w- c:\program files\Pcsx2
2010-01-31 10:20 . 2010-01-31 10:20 -------- d-----w- c:\program files\Common Files\Apple
2010-01-31 10:20 . 2010-01-31 10:20 -------- d-----w- c:\program files\Apple Software Update
2010-01-31 10:20 . 2010-01-31 10:20 -------- d-----w- c:\programdata\Apple
2010-01-31 10:17 . 2010-01-31 10:17 -------- d-----w- c:\users\Andrejko\AppData\Roaming\Thinstall
2010-01-21 13:53 . 2010-01-21 13:53 18048 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-01-13 09:20 . 2010-01-13 09:20 -------- d-----w- c:\programdata\BioWare
2010-01-13 08:44 . 2010-01-13 07:23 -------- d-----w- c:\program files\Common Files\BioWare
2010-01-13 00:44 . 2008-10-26 15:59 -------- d-----w- c:\program files\AGEIA Technologies
2010-01-11 15:55 . 2010-01-11 15:54 -------- d-----w- c:\users\Andrejko\AppData\Roaming\uTorrent
2010-01-06 15:38 . 2010-02-24 12:29 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-24 12:29 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 15:38 . 2010-02-24 12:29 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-24 12:29 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 10:18 . 2010-01-06 10:18 96 ----a-w- c:\users\Andrejko\AppData\Local\fusioncache.dat
2010-01-02 06:38 . 2010-01-24 20:46 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-24 20:46 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-24 20:46 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-24 20:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-30 10:30 . 2009-12-30 10:30 7936 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-12-30 10:30 . 2009-12-30 10:30 660480 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-12-30 10:30 . 2009-12-30 10:30 7936 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-12-30 10:30 . 2009-12-30 10:30 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-12-30 10:25 . 2009-12-30 10:25 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2009-12-30 10:25 . 2009-12-30 10:25 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2009-03-31 20:47 . 2009-04-22 10:33 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2009-03-01 22:08 . 2009-03-01 21:15 895008 --sha-w- c:\windows\System32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-01-29 430080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-29 4911104]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-10-25 413696]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-10-31 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-01-25 509816]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-07 198160]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-11-10 406016]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-10-20 340456]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-25 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
backup=c:\windows\pss\Bluetooth Manager.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desktop SMS]
2007-06-18 08:51 1507328 ----a-w- c:\program files\IDM\Desktop SMS\DesktopSMS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 15:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2006-12-06 01:44 366400 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
2008-01-21 02:23 215552 ----a-w- c:\windows\WindowsMobile\wmdSync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):91,64,a1,74,da,51,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2706454667-533331120-2221285752-1000]
"EnableNotificationsRef"=dword:00000001
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-25 691696]
R2 gupdate1ca5670872813c8;Služba Google Update (gupdate1ca5670872813c8);c:\program files\Google\Update\GoogleUpdate.exe [2009-10-26 133104]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-12-30 137344]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-12-30 8320]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2009-11-03 21520]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-03 126976]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder
2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-26 19:14]
2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-26 19:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.sk
mStart Page = about:blank
uInternet Settings,ProxyOverride = local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {4E7532CE-EE46-4735-BEC1-40CECF5761DC} = 10.0.0.254
FF - ProfilePath - c:\users\Andrejko\AppData\Roaming\Mozilla\Firefox\Profiles\vyyfj8i8.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - component: c:\program files\Mozilla Firefox\extensions\
linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Andrejko\AppData\Roaming\Mozilla\Firefox\Profiles\vyyfj8i8.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
AddRemove-ActiveScan 2.0 - c:\program files\Panda Security\ActiveScan 2.0\as2uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-09 23:13
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-03-09 23:19:13
ComboFix-quarantined-files.txt 2010-03-09 22:19
ComboFix2.txt 2010-03-09 07:13
Pre-Run: 66 215 829 504 bytes free
Post-Run: 65 984 352 256 bytes free
- - End Of File - - E64B83B73070BD4828315C789F411A29