Prosim o kontrolu logu-PC posiela SPAM
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Prosim o kontrolu logu-PC posiela SPAM
Moj PC posiela velke mnozstvo spamu. Uz som pouzil NOD, Eset online scanner, Spyware Terminator, AdAware, pricom najdene infiltracie som vymazal alebo ulozil do karanteny. Mam k PC pripojeny este 1TB externy HDD, aj ten mi preskenovali vyssie uvedene programy. Aj napriek tomu mi po zapnuti spamu zacne PC posielat kopec spamu. Chcel by preto som poprosit o kontrologu logu z RSIT. Vopred dakujem.
Logfile of random's system information tool 1.07 (written by random/random)
Run by mam-desktop at 2010-06-19 14:16:26
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (8%) free of 118 GB
Total RAM: 2047 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:16:40, on 19.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9488 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2
C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2010-06-19 14:16:26 ----D---- C:\rsit
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:52:50 ----A---- C:\ComboFix.txt
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 13:37:14 ----A---- C:\WINDOWS\zip.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWSC.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWREG.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\sed.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\PEV.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\NIRCMD.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\MBR.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\grep.exe
2010-06-19 13:37:03 ----D---- C:\WINDOWS\ERDNT
2010-06-19 13:34:30 ----AD---- C:\Qoobox
2010-06-19 12:05:37 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia
======List of files/folders modified in the last 1 months======
2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:50:08 ----D---- C:\WINDOWS
2010-06-19 13:50:08 ----A---- C:\WINDOWS\system.ini
2010-06-19 13:49:46 ----D---- C:\WINDOWS\Temp
2010-06-19 13:49:24 ----D---- C:\WINDOWS\system32
2010-06-19 13:48:12 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-19 13:46:35 ----D---- C:\WINDOWS\system32\drivers
2010-06-19 13:46:35 ----D---- C:\WINDOWS\AppPatch
2010-06-19 13:46:32 ----D---- C:\Program Files\Common Files
2010-06-19 13:43:01 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:37:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-19 13:21:37 ----D---- C:\Program Files\ArsClip
2010-06-19 13:18:12 ----SHD---- C:\WINDOWS\Installer
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:57:23 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 12:05:25 ----D---- C:\WINDOWS\system32\config
2010-06-19 11:39:18 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 11:37:08 ----D---- C:\WINDOWS\Debug
2010-06-19 11:37:07 ----D---- C:\WINDOWS\Minidump
2010-06-19 11:25:45 ----D---- C:\WINDOWS\Prefetch
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-19 11:03:42 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-17 00:06:52 ----HD---- C:\WINDOWS\inf
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\Restore
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 catchme;catchme; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\catchme.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys []
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
-----------------EOF-----------------
Logfile of random's system information tool 1.07 (written by random/random)
Run by mam-desktop at 2010-06-19 14:16:26
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (8%) free of 118 GB
Total RAM: 2047 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:16:40, on 19.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9488 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2
C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2010-06-19 14:16:26 ----D---- C:\rsit
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:52:50 ----A---- C:\ComboFix.txt
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 13:37:14 ----A---- C:\WINDOWS\zip.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWSC.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWREG.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\sed.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\PEV.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\NIRCMD.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\MBR.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\grep.exe
2010-06-19 13:37:03 ----D---- C:\WINDOWS\ERDNT
2010-06-19 13:34:30 ----AD---- C:\Qoobox
2010-06-19 12:05:37 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia
======List of files/folders modified in the last 1 months======
2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:50:08 ----D---- C:\WINDOWS
2010-06-19 13:50:08 ----A---- C:\WINDOWS\system.ini
2010-06-19 13:49:46 ----D---- C:\WINDOWS\Temp
2010-06-19 13:49:24 ----D---- C:\WINDOWS\system32
2010-06-19 13:48:12 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-19 13:46:35 ----D---- C:\WINDOWS\system32\drivers
2010-06-19 13:46:35 ----D---- C:\WINDOWS\AppPatch
2010-06-19 13:46:32 ----D---- C:\Program Files\Common Files
2010-06-19 13:43:01 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:37:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-19 13:21:37 ----D---- C:\Program Files\ArsClip
2010-06-19 13:18:12 ----SHD---- C:\WINDOWS\Installer
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:57:23 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 12:05:25 ----D---- C:\WINDOWS\system32\config
2010-06-19 11:39:18 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 11:37:08 ----D---- C:\WINDOWS\Debug
2010-06-19 11:37:07 ----D---- C:\WINDOWS\Minidump
2010-06-19 11:25:45 ----D---- C:\WINDOWS\Prefetch
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-19 11:03:42 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-17 00:06:52 ----HD---- C:\WINDOWS\inf
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\Restore
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 catchme;catchme; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\catchme.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys []
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
-----------------EOF-----------------
- Caroprd111
- VIP

- Příspěvky: 13492
- Registrován: 22 Bře 2009 20:48
- Místo/Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosim o kontrolu logu-PC posiela SPAM
Zdravím
Vložte sem log C:\ComboFix.txt
Nedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!
Vložte sem log C:\ComboFix.txtNedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!
Re: Prosim o kontrolu logu-PC posiela SPAM
Nech sa paci:
ComboFix 10-06-18.03 - mam-desktop 19.06.2010 13:43:23.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1305 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\fjhdyfhsn.bat
c:\windows\system32\office.exe
I:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-19 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 11:48 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
2010-05-22 10:29 . 2010-05-22 10:26 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 11:50 . 2010-02-09 10:34 741376 ----a-w- c:\windows\system32\drivers\qizefsf.sys
2010-06-19 11:48 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-19 11:21 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-19 10:57 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 09:39 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]
c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 17:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
--- Other Services/Drivers In Memory ---
*Deregistered* - qizefsf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-Wdf01000.sys
MSConfigStartUp-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
MSConfigStartUp-Ovi Files Update - c:\program files\Ovi Files\updater.exe
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
AddRemove-Nokia Ovi Suite - c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Nokia_Ovi_Suite_webinstaller_ALL.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-19 13:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qizefsf]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abcecigninajfgncahjnknkolinkmdjdfm"=hex:65,62,63,65,6a,6a,64,6b,6f,69,68,63,
6e,66,67,70,65,6e,64,6f,6b,6a,6c,67,63,6d,6a,68,65,6c,64,6d,62,6c,70,6c,65,\
"bbcecigninajfgncahgnjkgigagcolkmnpjf"=hex:61,62,68,67,6a,65,6d,6e,68,6c,67,6e,
6d,6e,64,61,68,6d,6a,63,62,6e,66,6f,68,61,6a,6a,62,6a,68,62,63,69,00,6c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\DkWLNP.dll
.
Completion time: 2010-06-19 13:52:49
ComboFix-quarantined-files.txt 2010-06-19 11:52
Pre-Run: 6 998 347 776 bytes free
Post-Run: 9 400 561 664 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /bootlogo
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 0B2CE0E4DCA546CFE513A02EF2749335
ComboFix 10-06-18.03 - mam-desktop 19.06.2010 13:43:23.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1305 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\fjhdyfhsn.bat
c:\windows\system32\office.exe
I:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-19 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 11:48 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
2010-05-22 10:29 . 2010-05-22 10:26 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 11:50 . 2010-02-09 10:34 741376 ----a-w- c:\windows\system32\drivers\qizefsf.sys
2010-06-19 11:48 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-19 11:21 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-19 10:57 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 09:39 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]
c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 17:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
--- Other Services/Drivers In Memory ---
*Deregistered* - qizefsf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-Wdf01000.sys
MSConfigStartUp-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
MSConfigStartUp-Ovi Files Update - c:\program files\Ovi Files\updater.exe
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
AddRemove-Nokia Ovi Suite - c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Nokia_Ovi_Suite_webinstaller_ALL.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-19 13:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qizefsf]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abcecigninajfgncahjnknkolinkmdjdfm"=hex:65,62,63,65,6a,6a,64,6b,6f,69,68,63,
6e,66,67,70,65,6e,64,6f,6b,6a,6c,67,63,6d,6a,68,65,6c,64,6d,62,6c,70,6c,65,\
"bbcecigninajfgncahgnjkgigagcolkmnpjf"=hex:61,62,68,67,6a,65,6d,6e,68,6c,67,6e,
6d,6e,64,61,68,6d,6a,63,62,6e,66,6f,68,61,6a,6a,62,6a,68,62,63,69,00,6c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\DkWLNP.dll
.
Completion time: 2010-06-19 13:52:49
ComboFix-quarantined-files.txt 2010-06-19 11:52
Pre-Run: 6 998 347 776 bytes free
Post-Run: 9 400 561 664 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /bootlogo
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 0B2CE0E4DCA546CFE513A02EF2749335
- Caroprd111
- VIP

- Příspěvky: 13492
- Registrován: 22 Bře 2009 20:48
- Místo/Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosim o kontrolu logu-PC posiela SPAM
Pokud nemáte, přesuňte Combofix na plochu
- Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.
Kód: Vybrat vše
File::
c:\windows\system32\drivers\qizefsf.sys
Driver::
qizefsf
RegLock::
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]- Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
- Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:

- Po aplikaci na Vás vypadne další log,vložte ho sem
Re: Prosim o kontrolu logu-PC posiela SPAM
ComboFix 10-06-18.03 - mam-desktop 19.06.2010 15:03:17.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1308 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mam-desktop\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FILE ::
"c:\windows\system32\drivers\qizefsf.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\qizefsf.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_QIZEFSF
-------\Service_qizefsf
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- C:\rsit
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- c:\program files\trend micro
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-19 13:15 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 11:48 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 13:14 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-19 13:11 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-19 12:41 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 10:57 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-22 10:26 . 2010-05-22 10:29 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]
c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 17:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [16.6.2010 19:18 142592]
R2 DkVcm;Datakey's Virtual Channel Monitor;c:\windows\system32\dkvcm.exe [23.11.2004 10:33 122880]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [28.1.2009 13:34 634488]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [25.9.2009 23:32 189736]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7.5.2010 18:04 1051976]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [25.2.2010 11:18 10064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [16.3.2004 3:04 18536]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-19 15:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abcecigninajfgncahjnknkolinkmdjdfm"=hex:65,62,63,65,6a,6a,64,6b,6f,69,68,63,
6e,66,67,70,65,6e,64,6f,6b,6a,6c,67,63,6d,6a,68,65,6c,64,6d,62,6c,70,6c,65,\
"bbcecigninajfgncahgnjkgigagcolkmnpjf"=hex:61,62,68,67,6a,65,6d,6e,68,6c,67,6e,
6d,6e,64,61,68,6d,6a,63,62,6e,66,6f,68,61,6a,6a,62,6a,68,62,63,69,00,6c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(924)
c:\windows\system32\DkWLNP.dll
- - - - - - - > 'explorer.exe'(572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\windows\System32\drprov.dll
c:\windows\System32\davclnt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\DkLog.exe
c:\windows\system32\SCardSvr.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\System32\dkcktkn.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
.
**************************************************************************
.
Completion time: 2010-06-19 15:21:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-19 13:21
ComboFix2.txt 2010-06-19 11:52
Pre-Run: 9 396 215 808 bytes free
Post-Run: 9 291 743 232 bytes free
- - End Of File - - 07D52D694205E150841019A3AD8D820C
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1308 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mam-desktop\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FILE ::
"c:\windows\system32\drivers\qizefsf.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\qizefsf.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_QIZEFSF
-------\Service_qizefsf
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- C:\rsit
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- c:\program files\trend micro
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-19 13:15 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 11:48 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 13:14 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-19 13:11 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-19 12:41 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 10:57 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-22 10:26 . 2010-05-22 10:29 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]
c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 17:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [16.6.2010 19:18 142592]
R2 DkVcm;Datakey's Virtual Channel Monitor;c:\windows\system32\dkvcm.exe [23.11.2004 10:33 122880]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [28.1.2009 13:34 634488]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [25.9.2009 23:32 189736]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7.5.2010 18:04 1051976]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [25.2.2010 11:18 10064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [16.3.2004 3:04 18536]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-19 15:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abcecigninajfgncahjnknkolinkmdjdfm"=hex:65,62,63,65,6a,6a,64,6b,6f,69,68,63,
6e,66,67,70,65,6e,64,6f,6b,6a,6c,67,63,6d,6a,68,65,6c,64,6d,62,6c,70,6c,65,\
"bbcecigninajfgncahgnjkgigagcolkmnpjf"=hex:61,62,68,67,6a,65,6d,6e,68,6c,67,6e,
6d,6e,64,61,68,6d,6a,63,62,6e,66,6f,68,61,6a,6a,62,6a,68,62,63,69,00,6c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(924)
c:\windows\system32\DkWLNP.dll
- - - - - - - > 'explorer.exe'(572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\windows\System32\drprov.dll
c:\windows\System32\davclnt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\DkLog.exe
c:\windows\system32\SCardSvr.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\System32\dkcktkn.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
.
**************************************************************************
.
Completion time: 2010-06-19 15:21:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-19 13:21
ComboFix2.txt 2010-06-19 11:52
Pre-Run: 9 396 215 808 bytes free
Post-Run: 9 291 743 232 bytes free
- - End Of File - - 07D52D694205E150841019A3AD8D820C
- Caroprd111
- VIP

- Příspěvky: 13492
- Registrován: 22 Bře 2009 20:48
- Místo/Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosim o kontrolu logu-PC posiela SPAM
Odinstalujte všechny emulátory virtuálních mechanik.
Stáhněte SPTD http://www.duplexsecure.com/en/downloads
- Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
- zvolte možnost Uninstall a restartujte PC.
Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
- Klikněte na "Disable" a restartujte PC.
Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe
Start > Spustit (Win + R)- Vyskočí okénko, zkopírujte do něj:
Kód: Vybrat vše
"%userprofile%\desktop\mbr" -t- Klikněte na OK
- Vytvoří se log s názvem mbr.log, vložte ho sem.
Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878Re: Prosim o kontrolu logu-PC posiela SPAM
Prikladam log z mbr:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
a log z gmer:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-06-19 16:11:49
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\pwldipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eBoost.sys (eBoostr Filter Driver/eBoostr.com)
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
---- EOF - GMER 1.0.15 ----
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
a log z gmer:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-06-19 16:11:49
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\pwldipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eBoost.sys (eBoostr Filter Driver/eBoostr.com)
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
---- EOF - GMER 1.0.15 ----
- Caroprd111
- VIP

- Příspěvky: 13492
- Registrován: 22 Bře 2009 20:48
- Místo/Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosim o kontrolu logu-PC posiela SPAM
tu prikladam druhy log z GMER:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-20 00:23:31
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\pwldipow.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xB837F88E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xB837F0EC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xB837EDCE]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xB8380938]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xB837EED8]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xB837EFC2]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xB837FBBC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xB837F3F4]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetInformationFile [0xB837F526]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xB837EBFC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xB837FB04]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xB837F70C]
---- Kernel code sections - GMER 1.0.15 ----
? C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys Systém nemôže nájsť zadaný súbor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1704] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eBoost.sys (eBoostr Filter Driver/eBoostr.com)
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}@abcecigninajfgncahjnknkolinkmdjdfm 0x65 0x62 0x63 0x65 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}@bbcecigninajfgncahgnjkgigagcolkmnpjf 0x61 0x62 0x68 0x67 ...
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-20 00:23:31
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\pwldipow.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xB837F88E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xB837F0EC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xB837EDCE]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xB8380938]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xB837EED8]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xB837EFC2]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xB837FBBC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xB837F3F4]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetInformationFile [0xB837F526]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xB837EBFC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xB837FB04]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xB837F70C]
---- Kernel code sections - GMER 1.0.15 ----
? C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys Systém nemôže nájsť zadaný súbor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1704] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eBoost.sys (eBoostr Filter Driver/eBoostr.com)
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}@abcecigninajfgncahjnknkolinkmdjdfm 0x65 0x62 0x63 0x65 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}@bbcecigninajfgncahgnjkgigagcolkmnpjf 0x61 0x62 0x68 0x67 ...
---- EOF - GMER 1.0.15 ----
- Caroprd111
- VIP

- Příspěvky: 13492
- Registrován: 22 Bře 2009 20:48
- Místo/Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosim o kontrolu logu-PC posiela SPAM
Znovu aplikujte skript do CF s tímto obsahem:
Jak se chová PC 
Kód: Vybrat vše
RegNull::
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]Re: Prosim o kontrolu logu-PC posiela SPAM
PC sa chova teraz uplne v pohode. Po restarte sa nezacne posielat spam, ako predtym (videl som to vo Firewall NODu, kde som videl ako service.exe posiela nieco a ked som to rozklikol, tak tam bolo asi 20-30 IP adries, s tym, ze vo vlastnostiach bolo ze sa jedna o SMTP, niektore IP adresy mali aj mena a boli to rozne mail.nieco a pod.. Posielalo to kopec MB, aj 500 MB za 15 min.).
Teraz to teda uz vobec nerobi a vsetko sa chova kludne a vo firewalle sa objavuju len veci, ktore viem co su (opera, spyware terminator a pod.). Dakujem Vam, zachranili ste ma pred dalsim odpojenim zo strany mojho providera. Fakt super pomoc, nema to chybu. Ste machri. Este raz dakujem.
Tu posielam log po aplikovani scriptu:
ComboFix 10-06-18.03 - mam-desktop 20.06.2010 13:06:59.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1399 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mam-desktop\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((( Files Created from 2010-05-20 to 2010-06-20 )))))))))))))))))))))))))))))))
.
2010-06-20 10:06 . 2010-06-20 10:06 -------- d-----w- C:\spoolerlogs
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- C:\rsit
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- c:\program files\trend micro
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-20 11:15 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 14:06 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
2010-05-22 10:29 . 2010-05-22 10:26 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-20 11:16 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-20 11:03 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-20 06:07 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 13:58 . 2009-04-11 19:34 -------- d-----w- c:\program files\Common Files\Ahead
2010-06-19 12:41 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-06-19_11.50.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-20 11:03 . 2010-06-20 11:03 16384 c:\windows\Temp\Perflib_Perfdata_348.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]
c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [16.6.2010 19:18 142592]
R2 DkVcm;Datakey's Virtual Channel Monitor;c:\windows\system32\dkvcm.exe [23.11.2004 10:33 122880]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [28.1.2009 13:34 634488]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [25.9.2009 23:32 189736]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7.5.2010 18:04 1051976]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [25.2.2010 11:18 10064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [16.3.2004 3:04 18536]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-20 13:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(804)
c:\windows\system32\DkWLNP.dll
- - - - - - - > 'explorer.exe'(2380)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\System32\drprov.dll
c:\windows\System32\davclnt.dll
.
Completion time: 2010-06-20 13:18:57
ComboFix-quarantined-files.txt 2010-06-20 11:18
ComboFix2.txt 2010-06-19 13:21
ComboFix3.txt 2010-06-19 11:52
Pre-Run: 9 464 238 080 bytes free
Post-Run: 9 467 666 432 bytes free
- - End Of File - - AACFBC8104F1F998E5FC6D5A1D4CDE04
Teraz to teda uz vobec nerobi a vsetko sa chova kludne a vo firewalle sa objavuju len veci, ktore viem co su (opera, spyware terminator a pod.). Dakujem Vam, zachranili ste ma pred dalsim odpojenim zo strany mojho providera. Fakt super pomoc, nema to chybu. Ste machri. Este raz dakujem.
Tu posielam log po aplikovani scriptu:
ComboFix 10-06-18.03 - mam-desktop 20.06.2010 13:06:59.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1399 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mam-desktop\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((( Files Created from 2010-05-20 to 2010-06-20 )))))))))))))))))))))))))))))))
.
2010-06-20 10:06 . 2010-06-20 10:06 -------- d-----w- C:\spoolerlogs
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- C:\rsit
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- c:\program files\trend micro
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-20 11:15 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 14:06 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
2010-05-22 10:29 . 2010-05-22 10:26 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-20 11:16 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-20 11:03 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-20 06:07 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 13:58 . 2009-04-11 19:34 -------- d-----w- c:\program files\Common Files\Ahead
2010-06-19 12:41 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-06-19_11.50.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-20 11:03 . 2010-06-20 11:03 16384 c:\windows\Temp\Perflib_Perfdata_348.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]
c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [16.6.2010 19:18 142592]
R2 DkVcm;Datakey's Virtual Channel Monitor;c:\windows\system32\dkvcm.exe [23.11.2004 10:33 122880]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [28.1.2009 13:34 634488]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [25.9.2009 23:32 189736]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7.5.2010 18:04 1051976]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [25.2.2010 11:18 10064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [16.3.2004 3:04 18536]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-20 13:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(804)
c:\windows\system32\DkWLNP.dll
- - - - - - - > 'explorer.exe'(2380)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\System32\drprov.dll
c:\windows\System32\davclnt.dll
.
Completion time: 2010-06-20 13:18:57
ComboFix-quarantined-files.txt 2010-06-20 11:18
ComboFix2.txt 2010-06-19 13:21
ComboFix3.txt 2010-06-19 11:52
Pre-Run: 9 464 238 080 bytes free
Post-Run: 9 467 666 432 bytes free
- - End Of File - - AACFBC8104F1F998E5FC6D5A1D4CDE04
- Caroprd111
- VIP

- Příspěvky: 13492
- Registrován: 22 Bře 2009 20:48
- Místo/Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosim o kontrolu logu-PC posiela SPAM
Ještě dočistíme po použitých nástrojích.
Odinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:
ComboFix /Uninstall
stiskněte Enter
Stáhněte T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
Dejte nový log z RSIT.
Odinstalujte ComboFix přes:Start >> Spustit, zkopírujte do okénka:
ComboFix /Uninstall
stiskněte Enter
Stáhněte T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
- Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
- Po použití program vymažte. Pozor, antiviry ho mohou falešně označit za vir.
Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
- Spusťte.
- Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)
Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
- Spusťte.
- Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)
Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
- Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.
Záložka Čistič - Dejte analyzovat, po dokončení dejte Spustit Ccleaner.
Záložka Registry - Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
OK
Zavřít
Dejte nový log z RSIT.Re: Prosim o kontrolu logu-PC posiela SPAM
Logfile of random's system information tool 1.07 (written by random/random)
Run by mam-desktop at 2010-06-20 14:50:35
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 11 GB (9%) free of 118 GB
Total RAM: 2047 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:50:42, on 20.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ICQ7.1\ICQ.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\mam-desktop\Desktop\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9709 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2
C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2010-06-20 14:50:35 ----D---- C:\rsit
2010-06-20 14:50:03 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-20 14:42:38 ----SHD---- C:\RECYCLER
2010-06-20 12:06:11 ----D---- C:\spoolerlogs
2010-06-19 15:52:34 ----D---- C:\Config.Msi
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia
======List of files/folders modified in the last 1 months======
2010-06-20 14:50:41 ----D---- C:\WINDOWS\Prefetch
2010-06-20 14:50:03 ----D---- C:\WINDOWS
2010-06-20 14:47:37 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-20 14:47:36 ----D---- C:\WINDOWS\Debug
2010-06-20 14:47:35 ----D---- C:\WINDOWS\Minidump
2010-06-20 14:47:04 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-20 14:45:27 ----D---- C:\WINDOWS\Temp
2010-06-20 14:45:05 ----D---- C:\Program Files\ArsClip
2010-06-20 14:44:12 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-06-20 14:42:38 ----D---- C:\WINDOWS\system32
2010-06-20 14:40:32 ----SHD---- C:\System Volume Information
2010-06-20 14:40:32 ----D---- C:\WINDOWS\system32\Restore
2010-06-20 14:26:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-20 13:16:15 ----A---- C:\WINDOWS\system.ini
2010-06-20 13:13:40 ----D---- C:\WINDOWS\system32\drivers
2010-06-20 13:13:40 ----D---- C:\WINDOWS\AppPatch
2010-06-20 13:13:37 ----D---- C:\Program Files\Common Files
2010-06-20 08:07:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 15:58:47 ----SHD---- C:\WINDOWS\Installer
2010-06-19 15:58:13 ----D---- C:\Program Files\Common Files\Ahead
2010-06-19 15:46:12 ----HD---- C:\WINDOWS\inf
2010-06-19 15:08:52 ----D---- C:\WINDOWS\system32\config
2010-06-19 14:53:16 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
-----------------EOF-----------------
Run by mam-desktop at 2010-06-20 14:50:35
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 11 GB (9%) free of 118 GB
Total RAM: 2047 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:50:42, on 20.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ICQ7.1\ICQ.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\mam-desktop\Desktop\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9709 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2
C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2010-06-20 14:50:35 ----D---- C:\rsit
2010-06-20 14:50:03 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-20 14:42:38 ----SHD---- C:\RECYCLER
2010-06-20 12:06:11 ----D---- C:\spoolerlogs
2010-06-19 15:52:34 ----D---- C:\Config.Msi
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia
======List of files/folders modified in the last 1 months======
2010-06-20 14:50:41 ----D---- C:\WINDOWS\Prefetch
2010-06-20 14:50:03 ----D---- C:\WINDOWS
2010-06-20 14:47:37 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-20 14:47:36 ----D---- C:\WINDOWS\Debug
2010-06-20 14:47:35 ----D---- C:\WINDOWS\Minidump
2010-06-20 14:47:04 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-20 14:45:27 ----D---- C:\WINDOWS\Temp
2010-06-20 14:45:05 ----D---- C:\Program Files\ArsClip
2010-06-20 14:44:12 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-06-20 14:42:38 ----D---- C:\WINDOWS\system32
2010-06-20 14:40:32 ----SHD---- C:\System Volume Information
2010-06-20 14:40:32 ----D---- C:\WINDOWS\system32\Restore
2010-06-20 14:26:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-20 13:16:15 ----A---- C:\WINDOWS\system.ini
2010-06-20 13:13:40 ----D---- C:\WINDOWS\system32\drivers
2010-06-20 13:13:40 ----D---- C:\WINDOWS\AppPatch
2010-06-20 13:13:37 ----D---- C:\Program Files\Common Files
2010-06-20 08:07:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 15:58:47 ----SHD---- C:\WINDOWS\Installer
2010-06-19 15:58:13 ----D---- C:\Program Files\Common Files\Ahead
2010-06-19 15:46:12 ----HD---- C:\WINDOWS\inf
2010-06-19 15:08:52 ----D---- C:\WINDOWS\system32\config
2010-06-19 14:53:16 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
-----------------EOF-----------------
- Caroprd111
- VIP

- Příspěvky: 13492
- Registrován: 22 Bře 2009 20:48
- Místo/Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosim o kontrolu logu-PC posiela SPAM
Jeeeej, super, faktazia. Strasne ste mi pomohli. Dakujem Vam aj vsetkym kto maju na svedomi tento web. Este raz velka vdaka.


Přispějete na provoz fóra?